While reviewing the security document set, an auditor notes that one document mandates a minimum password length of twelve characters that every system must enforce, while another only recommends that users choose passphrases they find easy to remember. What is the key difference between a standard and a guideline that explains why one is mandatory and the other is not?
- AA standard sets a mandatory requirement that must be met, while a guideline offers advisory recommendations that are not binding Correct
- BA standard applies only to technical staff, while a guideline applies to every employee in the organisation
- CA standard is a temporary measure pending approval, while a guideline is the permanent version once it is ratified
- DA standard is written by external regulators, while a guideline is written internally by the security team
Why A is correct: Correct: standards are compulsory and enforceable requirements that support a policy, whereas guidelines are recommended good practice that staff may adapt.
Why B is wrong: Tempting because audiences can differ, but the mandatory or advisory nature of a document is not determined by which audience it targets.
Why C is wrong: Tempting because document lifecycles exist, but standards and guidelines are distinct document types rather than draft and final versions of the same document.
Why D is wrong: Tempting because regulators do issue standards, but internal standards are common, so authorship does not define whether a document is mandatory.