SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationHard
A security team is implementing a new security policy that dictates all remote access to internal resources must use multi-factor authentication (MFA). Which of the following components of a security policy framework does this specific requirement fall under?
- AGuideline
- BProcedure
- CStandard
- DOrganizational Policy
Show answer & explanationAnswer & explanation
Correct answer: C. Standard
A standard provides mandatory rules describing the specific use of technology, processes, or configurations. Requiring all remote access to use MFA is a specific, mandatory rule for a technology/process, thus making it a standard within the security policy framework.
Why the other options are wrong
- A. A Guideline offers recommendations or best practices, which are not mandatory.
- B. A Procedure provides step-by-step instructions on how to implement a standard, not the requirement itself.
- D. Organizational Policy is a high-level statement of management's intent, not specific technical requirements.
Security Policy Standard
A mandatory rule or specification that defines the specific use of technology, processes, or configurations to ensure compliance with a high-level organizational security policy.
- Mandatory compliance.
- Specific and technical.
- Supports high-level policies.
- Often includes configuration requirements.
Memory trick: Policy is King, Standards are Laws, Guidelines are Advice, Procedures are Steps.