Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

A defense technology enterprise is updating its security management framework to enforce minimum host configuration states across all endpoint devices. The cybersecurity team must publish a mandatory governance document that explicitly defines the compulsory security settings, patch levels, and feature configurations required for a system to be permitted on the network. Which of the following governance document types best satisfies this requirement?

  1. Security baselineCevap
  2. B
    Security guideline
  3. C
    Standard operating procedure
  4. D
    Acceptable use policy

Cevap

Security baseline is the correct governance document type because it specifies compulsory minimum technical configurations that endpoints must maintain.
A security baseline establishes a compulsory, minimum security hardening standard that all enterprise systems must meet prior to deployment or operational access. It defines exact settings, such as enabled encryption, minimum OS patch revisions, and restricted services.

Adım Adım Çözüm

1
Analyze the requirement described in the scenario.
The enterprise requires a mandatory governance document establishing minimum technical configuration thresholds for endpoints.
Governance documents serve distinct purposes across policy, standard, baseline, guideline, and procedure levels.
2
Evaluate the choices against the governance policy hierarchy.
Baselines set non-negotiable minimum security hardening thresholds, standards mandate specific technical implementations, guidelines offer voluntary recommendations, and procedures define operational steps.
Identifying the document responsible for enforcing mandatory system configuration minimums points directly to a security baseline.

Anahtar Kavram

Security Governance Structures and Policy Frameworks
Bu soruyu puanla