An enterprise policy states that access to confidential data must be restricted to authorised users. A risk practitioner reviewing the control library notes that no document specifies the minimum password length, lockout threshold, or multi-factor requirement that systems must enforce. Which instrument is missing from the policy hierarchy?
- AA procedure describing the step-by-step tasks an administrator follows to reset a forgotten user password on request.
- BA guideline suggesting good practices that teams may consider when configuring access for confidential information stores.
- CA baseline configuration template applied only to a single legacy database server hosting confidential records.
- DA standard defining the mandatory minimum control parameters that systems must meet to satisfy the access policy. Correct
Why A is wrong: A procedure documents how a task is performed, but it does not set the mandatory measurable requirements that systems must meet, so the gap remains.
Why B is wrong: A guideline is advisory and optional, so it cannot define the enforceable thresholds the policy intent depends on; this is a tempting but wrong fit.
Why C is wrong: A device baseline configures one platform rather than setting the enterprise-wide mandatory parameters the policy requires; it is too narrow to close the gap.
Why D is correct: A standard translates broad policy intent into specific, mandatory, measurable requirements such as password length and lockout thresholds, which is exactly the missing layer.