Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

A newly hired security manager at a healthcare technology company is organizing the documentation repository to distinguish between mandatory compliance directives and discretionary guidance. Which of the following documents constitute mandatory elements of an enterprise security governance framework? (Select TWO.)

  1. An organizational Information Security Standard mandating minimum encryption strength for stored patient recordsCevap
  2. An Enterprise Security Policy establishing executive management's overarching directives and commitment to data protectionCevap
  3. C
    A vendor-provided Security Guideline describing recommended configuration choices for web application performance
  4. D
    A technical architectural diagram detailing network subnets and firewall placements across regional data centers
  5. E
    An access control table specifying individual database read and write authorization permissions for authenticated users

Cevap

The mandatory governance elements are the organizational Information Security Standard and the Enterprise Security Policy.
In security governance hierarchies, policies represent high-level mandatory directives issued by executive management, while standards define mandatory compulsory technical or operational controls required to enforce those policies.

Adım Adım Çözüm

1
Distinguish mandatory governance documents from discretionary documents.
Policies and standards are compulsory within an enterprise, while guidelines are advisory and optional.
Governance frameworks rely on policies for authority and standards for mandatory technical implementation rules.
2
Evaluate the candidate options against compulsory governance criteria.
The Information Security Standard enforces mandatory technical specifications, and the Enterprise Security Policy enacts mandatory executive directives.
Both documents establish required compliance rules that personnel must follow.
3
Analyze the remaining distractor options.
Guidelines are optional recommendations, network diagrams are reference artifacts, and access control tables enforce technical authorization.
None of these distractors represent mandatory policy or standard level governance documents.

Anahtar Kavram

Security Governance Hierarchy: Mandatory Policies and Standards vs. Discretionary Guidelines
Tahmini Süre:1m 30s
Bu soruyu puanla