ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityEasy

A company is implementing a new policy for handling 'Confidential' data. The policy states that all such data must be stored on encrypted file shares, accessed only by authorized personnel, and automatically subject to a 7-year retention period. Which type of data security control is the 'encrypted file shares' requirement an example of?

  1. ATechnical Control
  2. BCompensating Control
  3. CPhysical Control
  4. DAdministrative Control
Show answer & explanation

Correct answer: A. Technical Control

Encrypted file shares are implemented through software and/or hardware to protect data. They automatically enforce confidentiality by rendering data unreadable without the correct key. This makes them a clear example of a technical control.

Why the other options are wrong

  • B. Compensating controls mitigate risk when a primary control cannot be implemented, which isn't the primary classification here.
  • C. Physical controls protect the physical environment, not digital data directly.
  • D. Administrative controls are policies and procedures, not direct technological implementations.

Technical Controls

Security controls implemented through hardware or software to enforce security policies and protect systems and data.

  • Automate security functions.
  • Examples: firewalls, IDS, encryption, access control systems.
  • Directly protect assets.

Memory trick: Admin's Rules, Physical's Walls, Technical's Code, Operational's Calls.

More Asset Security questions