Match each security governance document type to its corresponding operational characteristic within an enterprise governance framework.
- Security PolicyHigh-level organizational directive that defines mandatory security objectives and administrative authority.
- Security StandardMandatory course of action or technical requirement that enforces specific compliance rules across the organization.
- Security GuidelineDiscretionary recommendation or best practice that offers operational advice without strict compliance enforcement.
- Security BaselineMandatory minimum security configuration threshold applied to specific systems or operational environments.
Cevap
Security Policy matches the high-level directive statement; Security Standard matches the mandatory compliance requirement; Security Guideline matches the discretionary advice; Security Baseline matches the minimum configuration threshold.
In security governance, documents follow a formal hierarchy: Policies provide top-down executive leadership direction; Standards define mandatory procedural and technical requirements; Guidelines offer non-binding best practice advice; and Baselines establish minimum security build configurations for IT assets.
Adım Adım Çözüm
Anahtar Kavram
Security Governance Document Hierarchy and Enforceability