SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationHard

A security team is implementing a new security policy that dictates all remote access to internal resources must use multi-factor authentication (MFA). Which of the following components of a security policy framework does this specific requirement fall under?

  1. AGuideline
  2. BProcedure
  3. CStandard
  4. DOrganizational Policy
Show answer & explanation

Correct answer: C. Standard

A standard provides mandatory rules describing the specific use of technology, processes, or configurations. Requiring all remote access to use MFA is a specific, mandatory rule for a technology/process, thus making it a standard within the security policy framework.

Why the other options are wrong

  • A. A Guideline offers recommendations or best practices, which are not mandatory.
  • B. A Procedure provides step-by-step instructions on how to implement a standard, not the requirement itself.
  • D. Organizational Policy is a high-level statement of management's intent, not specific technical requirements.

Security Policy Standard

A mandatory rule or specification that defines the specific use of technology, processes, or configurations to ensure compliance with a high-level organizational security policy.

  • Mandatory compliance.
  • Specific and technical.
  • Supports high-level policies.
  • Often includes configuration requirements.

Memory trick: Policy is King, Standards are Laws, Guidelines are Advice, Procedures are Steps.

More Security Operations and Administration questions