Following an enterprise-wide cloud transformation, an organization's Chief Information Security Officer (CISO) establishes a multi-tiered governance structure to enforce security controls across diverse engineering teams. The framework includes high-level security objectives, mandatory technical requirements for microservices, discretionary coding recommendations, and platform-specific step-by-step configuration steps. During an internal compliance review, a software development team is flagged for utilizing AES-128 encryption across microservices instead of the mandatory enterprise cipher specification. The team lead asserts that technical rules specified outside the overarching executive policy document are non-binding recommendations. Which governance document type did the CISO issue to enforce mandatory technical requirements across the enterprise, and what is its role within the governance hierarchy?
- Standard; it establishes mandatory technical specifications and rules that operationalize high-level security policies.Cevap
- BGuideline; it provides mandatory operational commands designed to offer engineering teams flexibility during deployment.
- CPolicy; it details granular system-level configurations and step-by-step execution workflows for cloud platform microservices.
- DBaseline; it serves as a discretionary reference model designed purely to inform voluntary implementation choices.