ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium

A financial institution processes Personally Identifiable Information (PII) for millions of customers. A new regulatory requirement mandates that all PII used for marketing purposes must be logically segregated from operational PII and subject to stricter access controls. Which data security control category does this requirement primarily fall under?

  1. ADetective controls
  2. BPhysical controls
  3. CAdministrative controls
  4. DTechnical controls
Show answer & explanation

Correct answer: D. Technical controls

Logical segregation and stricter access controls are implemented through software and hardware mechanisms, such as network segmentation, database permissions, and access control lists. These are classic examples of technical controls.

Why the other options are wrong

  • A. Detective controls identify incidents after they occur, rather than preventing them or enforcing segregation directly.
  • B. Physical controls relate to securing the physical environment, not logical data separation.
  • C. Administrative controls are policies and procedures, not the direct implementation of segregation.

Technical Controls

Security safeguards that are implemented through hardware, software, or firmware to protect systems and information.

  • Use technology to enforce security policies.
  • Examples: firewalls, intrusion detection systems, access control lists, encryption.
  • Can be preventative, detective, or corrective.

Memory trick: Admin tells, Tech does, Physical blocks, Detective watches.

More Asset Security questions