CISM Certified Information Security Manager – Question0015

Minimum standards for securing the technical infrastructure should be defined in a security:

A.
strategy.
B. guidelines.
C. model.
D. architecture.

Correct Answer: D

Explanation:

Explanation:
Minimum standards for securing the technical infrastructure should be defined in a security architecture document. This document defines how components are secured and the security services that should be in place. A strategy is a broad, high-level document. A guideline is advisory in nature, while a security model shows the relationships between components.