Following an internal compliance audit that revealed inconsistent server hardening across cloud environments, a technology firm needs to publish a mandatory document defining the minimum required technical security settings—such as disabled protocols and required encryption key lengths—that every system must satisfy before deployment. Which of the following governance document types should the security team establish to enforce these mandatory minimum technical settings?
- BaselineCevap
- BGuideline
- CProcedure
- DPolicy
Cevap
Baseline
A security baseline specifies the mandatory minimum security configuration settings and system hardening requirements that all host systems or applications must conform to before entering production. In this scenario, creating a baseline ensures consistent minimum security thresholds across all deployed infrastructure.
Adım Adım Çözüm
Anahtar Kavram
Security Baseline Configurations in Governance Hierarchy