CompTIA Project+ (PK0-005)Basics of IT and GovernanceMedium

A company is implementing a new ERP system. The project manager identifies a significant risk: the system's database could be compromised, leading to unauthorized access to sensitive financial data. To mitigate this risk, the project team decides to encrypt the database at rest and in transit, implement strong access controls, and regularly audit database access logs. Which security control category do these actions primarily fall under?

  1. ATechnical Controls
  2. BAdministrative Controls
  3. CPhysical Controls
  4. DOperational Controls
Show answer & explanation

Correct answer: A. Technical Controls

Encrypting data, implementing access controls within a system, and auditing logs are all technical measures enforced by systems and software, thus falling under Technical Controls.

Why the other options are wrong

  • B. Administrative Controls are policies, procedures, and guidelines (e.g., security awareness training).
  • C. Physical Controls involve tangible measures like locks, fences, or security guards.
  • D. Operational Controls are day-to-day security activities, often a blend of administrative and technical, but the core actions here are technical implementations.

Technical Controls

Technical controls are security safeguards implemented through hardware, software, or firmware to protect information systems and data.

  • Enforced by technology (e.g., encryption, firewalls, access control lists).
  • Automate and manage protection of resources.
  • Contrast with administrative (policies) and physical (tangible) controls.

Memory trick: TAP: Technical, Admin, Physical covers all controls.

More Basics of IT and Governance questions