ISC2 Certified in Cybersecurity (CC)Security PrinciplesEasy

A company is implementing a new policy that requires all employees to complete a mandatory online course on phishing awareness. What type of security control is this policy primarily categorized as?

  1. ATechnical control
  2. BPhysical control
  3. COperational control
  4. DAdministrative control
Show answer & explanation

Correct answer: D. Administrative control

Security awareness training, mandated by a policy, is an administrative control as it involves policies, procedures, and training to manage security.

Why the other options are wrong

  • A. Technical controls use technology to protect assets (e.g., firewalls, encryption).
  • B. Physical controls protect physical assets (e.g., locks, cameras).
  • C. Operational controls are specific methods and procedures for day-to-day security tasks, often stemming from administrative controls.

Administrative Control

Security controls implemented through policies, procedures, guidelines, and training to manage security risks.

  • Focuses on people and processes.
  • Examples include security policies, incident response plans, and security awareness training.
  • Forms the foundation for technical and physical controls.

Memory trick: Think of security controls like a house: Administrative is the blueprints, Technical is the alarm system, Physical is the locks and fences.

More Security Principles questions