CISM · Question #942
The security baselines of an organization should be based on:
The correct answer is C. standards. Standards define the specific, mandatory requirements that security baselines must meet - they are measurable, enforceable, and technology-specific (e.g., "all passwords must be 12+ characters"), making them the natural foundation for baselines. Policies (A) are too high-level…
Question
The security baselines of an organization should be based on:
Options
- Apolicies.
- Bguidelines.
- Cstandards.
- Dprocedures.
How the community answered
(26 responses)- A8% (2)
- B4% (1)
- C85% (22)
- D4% (1)
Explanation
Standards define the specific, mandatory requirements that security baselines must meet - they are measurable, enforceable, and technology-specific (e.g., "all passwords must be 12+ characters"), making them the natural foundation for baselines.
Policies (A) are too high-level - they state what must be done ("data must be protected") but not how, so they can't anchor a technical baseline. Guidelines (B) are advisory and optional, meaning they carry no enforcement weight and can't reliably define a minimum security posture. Procedures (D) describe step-by-step how to implement something, which comes after a baseline is established, not before.
Memory tip: Think of the hierarchy - Policies → Standards → Baselines → Procedures. Baselines are a concrete expression of standards, so they must be based on standards. The word "baseline" itself implies a measurable minimum, which only standards (not optional guidelines) can provide.
Topics
Community Discussion
No community discussion yet for this question.