312-50V9 · Question #175
Which type of security document is written with specific step-by-step details?
The correct answer is B. Procedure. Security documentation has distinct types with different levels of specificity. A procedure provides the granular, step-by-step instructions for completing a task.
Question
Which type of security document is written with specific step-by-step details?
Options
- AProcess
- BProcedure
- CPolicy
- DParadigm
How the community answered
(20 responses)- A10% (2)
- B85% (17)
- C5% (1)
Why each option
Security documentation has distinct types with different levels of specificity. A procedure provides the granular, step-by-step instructions for completing a task.
A process describes a series of related actions or steps at a higher, often cross-functional level without the granular step-by-step detail that defines a procedure.
A procedure is the most specific type of security document, providing detailed, sequential steps that a user must follow to complete a task. Unlike policies (which state rules) or processes (which describe workflows at a higher level), procedures leave no ambiguity about exactly how an action must be performed. This level of detail makes them the authoritative reference for repeatable operational tasks.
A policy defines organizational rules, requirements, and acceptable behavior but does not contain specific how-to instructions.
Paradigm is a conceptual model or framework, not a recognized category of security documentation.
Concept tested: Security document types - policy vs procedure vs process
Source: https://csrc.nist.gov/publications/detail/sp/800-12/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.