A risk committee is debating whether two new documents should be drafted as standards or as guidelines. The first will require all internet-facing web services to enforce a named transport encryption configuration; the second will suggest preferred ways for staff to label sensitive files on shared drives. Which classification best reflects accepted security-document practice?
- ADraft both documents as standards, so that legal and audit teams have clear evidence of mandatory enforcement.
- BDraft the transport encryption document as a standard and the file-labelling document as a guideline, matching mandatory and advisory intent. Correct
- CDraft both documents as guidelines, because operational staff need flexibility to adapt controls to their own work patterns.
- DDraft the transport encryption document as a procedure and the file-labelling document as a baseline configuration.
Why A is wrong: Making advisory file-labelling content a standard would impose obligatory rules where flexibility is desired and would dilute the meaning of 'standard' across the document set.
Why B is correct: Standards are mandatory and prescriptive, suitable for an enforceable encryption configuration, while guidelines are advisory and well suited to recommended, judgement-based practices such as labelling sensitive files.
Why C is wrong: Internet-facing encryption is a control the organisation must be able to enforce and audit; treating it as advisory would weaken assurance and breach common regulatory expectations.
Why D is wrong: A procedure describes step-by-step actions and a baseline defines a minimum configuration; neither captures the mandatory-versus-advisory distinction the committee actually has to choose between.