Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

A biotechnology organization is establishing its security governance documentation. Executive leadership mandates the creation of an overarching, non-technical document that outlines management's strategic intent, defines security goals, and establishes mandatory rules for protecting intellectual property across the entire enterprise. Which security governance document type must executive leadership issue to satisfy this requirement?

  1. Organizational Security PolicyCevap
  2. B
    Security Guideline
  3. C
    Technical Security Baseline
  4. D
    Standard Operating Procedure

Cevap

Organizational Security Policy
An Organizational Security Policy is a high-level, executive-approved document that defines management's intent, security objectives, and mandatory expectations for the entire enterprise. It serves as the foundation of the security governance framework and remains deliberately non-technical to maintain long-term relevance.

Adım Adım Çözüm

1
Analyze the scenario requirements
Identified key requirements: executive leadership authority, high-level strategic intent, non-technical focus, broad enterprise scope, and mandatory compliance.
Governance documents occupy distinct tiers within the security documentation hierarchy based on authority level, scope, and technical granularity.
2
Compare requirements against the security governance documentation hierarchy
High-level strategic directives issued by management align with policies. Specific technical configurations align with baselines, discretionary recommendations align with guidelines, and detailed action steps align with procedures.
Policies establish top-level goals and mandatory compliance; standards and baselines enforce uniform configuration rules; guidelines advise; procedures define steps.
3
Select the matching governance document
The Organizational Security Policy fulfills executive leadership's mandate for an overarching strategic directive.
Policies serve as the foundation of security governance by formalizing executive commitment and steering organizational security behavior.

Anahtar Kavram

Security Governance Hierarchy (Policy vs. Standard vs. Baseline vs. Guideline vs. Procedure)
Bu soruyu puanla