Security documentation forms a hierarchy, and the exam likes to ask which document type fits a description. Each layer answers a different question: why and what (policy), which specific requirements (standards and baselines), how, step by step (procedures) and what we recommend (guidelines). Knowing whether each document is mandatory or optional is often the key to the right answer, and knowing who approves each one tells you how hard it is to change.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.