A county assessor’s office needs encryption and logging baselines for resident tax files. Leadership wants something defensible at audit time, not tips pulled from random blogs. How should the security architect select those standards?
Select an answer to reveal the explanation.
Short Explanation
Think of standards like building codes for the courthouse—you follow what the city already adopted, then tweak for the tax vault. Grabbing random blog ciphers is like wiring the building from a weekend DIY video: clever until the inspector shows up.
Full Explanation
Data-protection requirements should map to adopted organizational or regulatory frameworks so control selection is consistent and auditable. Tailoring those baselines to classification and handling rules preserves proportionality. Ad-hoc blog guidance and one-off local policies create uneven protection and weak evidence during reviews.