A defense technology enterprise is updating its security management framework to enforce minimum host configuration states across all endpoint devices. The cybersecurity team must publish a mandatory governance document that explicitly defines the compulsory security settings, patch levels, and feature configurations required for a system to be permitted on the network. Which of the following governance document types best satisfies this requirement?
- Security baselineCevap
- BSecurity guideline
- CStandard operating procedure
- DAcceptable use policy
Cevap
Security baseline is the correct governance document type because it specifies compulsory minimum technical configurations that endpoints must maintain.
A security baseline establishes a compulsory, minimum security hardening standard that all enterprise systems must meet prior to deployment or operational access. It defines exact settings, such as enabled encryption, minimum OS patch revisions, and restricted services.
Adım Adım Çözüm
Anahtar Kavram
Security Governance Structures and Policy Frameworks