ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityEasy
A company is implementing a new policy for handling 'Confidential' data. The policy states that all such data must be stored on encrypted file shares, accessed only by authorized personnel, and automatically subject to a 7-year retention period. Which type of data security control is the 'encrypted file shares' requirement an example of?
- ATechnical Control
- BCompensating Control
- CPhysical Control
- DAdministrative Control
Show answer & explanationAnswer & explanation
Correct answer: A. Technical Control
Encrypted file shares are implemented through software and/or hardware to protect data. They automatically enforce confidentiality by rendering data unreadable without the correct key. This makes them a clear example of a technical control.
Why the other options are wrong
- B. Compensating controls mitigate risk when a primary control cannot be implemented, which isn't the primary classification here.
- C. Physical controls protect the physical environment, not digital data directly.
- D. Administrative controls are policies and procedures, not direct technological implementations.
Technical Controls
Security controls implemented through hardware or software to enforce security policies and protect systems and data.
- Automate security functions.
- Examples: firewalls, IDS, encryption, access control systems.
- Directly protect assets.
Memory trick: Admin's Rules, Physical's Walls, Technical's Code, Operational's Calls.