An enterprise security governance team is restructuring organizational documentation to ensure clear operational authority and compliance across all business units. Match each security governance document type on the left with its correct legal and operational description on the right.
- Acceptable Use Policy (AUP)High-level, mandatory directive issued by senior management defining acceptable employee behaviors and operational constraints when utilizing enterprise assets.
- Data Classification StandardMandatory requirement specifying compulsory schemas, procedures, and controls to categorize and handle information assets according to sensitivity.
- Server Security BaselineMandatory operational threshold detailing the minimum required security configuration settings for system deployments prior to production introduction.
- Remote Work Security GuidelineDiscretionary recommendations and advisory best practices providing flexible suggestions for securing home workspace environments without strict mandatory enforcement.
Cevap
Acceptable Use Policy matches the high-level mandatory directive; Data Classification Standard matches the mandatory schema for categorizing assets; Server Security Baseline matches the mandatory minimum configuration threshold; Remote Work Security Guideline matches the discretionary best practices recommendations.
In security governance hierarchies, Policies (such as an Acceptable Use Policy) represent senior management's mandatory high-level directives. Standards (such as a Data Classification Standard) provide mandatory, specific rules and schemas supporting policy execution. Baselines (such as a Server Security Baseline) define the minimum required operational configurations needed to establish a consistent security floor. Guidelines (such as Remote Work Security Guidelines) offer discretionary, non-mandatory advice and best practices for operational flexibility.
Adım Adım Çözüm
Anahtar Kavram
Information Security Policy and Governance Hierarchy Document Types