Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

An enterprise logistics organization is updating its security governance documentation framework following an audit review. As part of this initiative, the information security team publishes a document outlining recommended best practices for securing remote home-office wireless routers. The document offers advisory tips for optimizing router posture but explicitly leaves compliance to the discretion of individual employees. Which of the following document types within the security governance hierarchy best categorizes this publication?

  1. GuidelineCevap
  2. B
    Standard
  3. C
    Baseline
  4. D
    Procedure

Cevap

The published document is a Guideline because it provides advisory recommendations and best practices with discretionary compliance rather than mandatory enforcement.
In security governance, Guidelines represent advisory, non-mandatory documentation that offers recommendations and best practices. Because the logistics organization's document provides router security advice while leaving compliance optional for employees, it strictly meets the definition of a Guideline.

Adım Adım Çözüm

1
Analyze the operational intent and enforcement nature of the document in the scenario.
The document contains recommended best practices and tips where compliance is explicitly discretionary.
Governance documents are categorized primarily by whether they are mandatory or advisory.
2
Evaluate the governance document hierarchy definitions against the scenario characteristics.
Guidelines are optional/discretionary best practices; Policies define high-level management intent; Standards establish mandatory requirements; Baselines define minimum mandatory configurations; Procedures detail step-by-step instructions.
Identifying the distinct enforcement level of each governance tier determines the proper classification.
3
Select the governance document type that matches optional recommendations.
Guideline is the correct document type.
Only guidelines represent non-mandatory recommendations within standard security policy frameworks.

Anahtar Kavram

Security Governance Policy Hierarchy (Policies, Standards, Baselines, Guidelines, Procedures)
Bu soruyu puanla