Soru

Zorluk: KolaySecurity Governance Structures and Policy Frameworks

A security analyst is reviewing a high-level organizational document that explicitly states all company-owned endpoints must enforce encryption at rest to protect sensitive data. The document provides overall leadership direction and is mandatory for all employees, but it does not detail specific software configurations or step-by-step commands. Which of the following governance document types best describes this document?

  1. PolicyCevap
  2. B
    Guideline
  3. C
    Baseline
  4. D
    Procedure

Cevap

Policy
A security policy is a high-level directive issued by senior management that sets mandatory requirements and principles for protecting organizational assets without prescribing specific implementation steps.

Adım Adım Çözüm

1
Analyze the scope and authority described in the scenario.
The document comes from leadership, covers the whole organization, and is mandatory.
Governance documents are categorized based on their level of abstraction and mandatory enforcement.
2
Differentiate high-level strategic directives from implementation details.
The document sets mandatory goals (enforce encryption) without specifying technical steps or specific software tools.
Policies set the strategic intent and high-level requirements, leaving detailed technical specifications to standards, baselines, and procedures.

Anahtar Kavram

Security Policy Hierarchy and Document Types
Bu soruyu puanla