Following an executive directive mandating strict software supply chain security, an enterprise security architect publishes a technical document for application development teams. The document establishes mandatory technical criteria, including requiring all container images to be cryptographically signed and prohibiting deployment if any unresolved critical vulnerabilities are detected. While the document does not outline tool-specific step-by-step workflow actions, adherence to these quantitative rules is strictly compulsory across all engineering teams. Which of the following security governance document types is represented by this technical specification?
- AGuideline
- StandardCevap
- CBaseline
- DProcedure
Cevap
Standard
A security standard specifies mandatory technical, operational, or behavioral rules that support high-level enterprise policies. Because the document introduces mandatory technical criteria (container signature verification and zero critical vulnerability thresholds) that must be strictly followed without defining step-by-step tactical instructions, it functions as a security standard.
Adım Adım Çözüm
Anahtar Kavram
Security Governance Hierarchy (Policies, Standards, Baselines, Guidelines, Procedures)