A Chief Information Security Officer (CISO) at a global logistics firm is updating the corporate cybersecurity governance framework to clarify the enforceability of various security documents. Which of the following governance document types establish MANDATORY compliance requirements that enterprise personnel must follow? (Select TWO)
- Information Security Policy defining acceptable data handling and employee security responsibilitiesCevap
- Enterprise Encryption Standard specifying approved algorithms, minimum key lengths, and cipher suitesCevap
- CRemote Work Best Practices Guideline outlining recommended home network configurations for teleworkers
- DIncident Response Playbook detailing step-by-step technical execution steps for firewall isolation
- EPrivileged Access Authorization Matrix mapping individual user permissions to administrative roles
Cevap
The governance document types that establish mandatory compliance requirements are the Information Security Policy defining acceptable data handling and the Enterprise Encryption Standard specifying approved algorithms and key lengths.
In security governance frameworks, both policies and standards carry mandatory compliance obligations. An Information Security Policy serves as an executive mandate that sets high-level organizational security goals and expectations. An Enterprise Encryption Standard establishes compulsory technical specifications (such as mandatory key lengths and approved algorithms) required to achieve the policy objectives.
Adım Adım Çözüm
Anahtar Kavram
Security Governance Hierarchy (Policies and Standards as Mandatory Directives vs Guidelines and Procedures)