Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

A satellite communications provider is formalizing its enterprise security oversight framework following a regulatory audit. Security analysts must properly categorize governance artifacts to establish clear organizational hierarchy. Match each security governance document type on the left with its defining operational characteristic on the right.

  • Security PolicyHigh-level management directive that outlines strategic security goals, roles, and overall organizational commitment.
  • Security StandardMandatory course of action specifying uniform technical requirements, metrics, or control thresholds.
  • Security BaselineMinimum required security configuration state established for a specific operating system or cloud platform deployment.
  • Security GuidelineDiscretionary recommendation offering operational advice and best practices without strict enforcement.

Cevap

Security Policy matches the high-level executive directive; Security Standard matches mandatory uniform technical requirements; Security Baseline matches minimum configuration state; Security Guideline matches discretionary recommendations.
In security governance hierarchy, policies dictate high-level executive intent, standards enforce mandatory technical specifications, baselines define minimum technical system configurations, and guidelines provide non-mandatory best practices.

Adım Adım Çözüm

1
Identify top-level authority documents.
Map Security Policy to high-level management directives establishing strategic goals.
Policies represent high-level managerial intent and set foundational security scope.
2
Distinguish mandatory requirements from minimum system states.
Map Security Standard to mandatory technical requirements/metrics and Security Baseline to minimum deployment configuration states.
Standards dictate mandatory rules, while baselines set specific platform configuration minimums.
3
Identify non-mandatory governance elements.
Map Security Guideline to discretionary recommendations and operational advice.
Guidelines provide non-binding recommendations where flexibility is permitted.

Anahtar Kavram

Hierarchy of Security Governance Documents
Tahmini Süre:1m 30s
Bu soruyu puanla