ISC2 Certified in Cybersecurity (CC)Security PrinciplesEasy
A company is implementing a new policy that requires all employees to complete a mandatory online course on phishing awareness. What type of security control is this policy primarily categorized as?
- ATechnical control
- BPhysical control
- COperational control
- DAdministrative control
Show answer & explanationAnswer & explanation
Correct answer: D. Administrative control
Security awareness training, mandated by a policy, is an administrative control as it involves policies, procedures, and training to manage security.
Why the other options are wrong
- A. Technical controls use technology to protect assets (e.g., firewalls, encryption).
- B. Physical controls protect physical assets (e.g., locks, cameras).
- C. Operational controls are specific methods and procedures for day-to-day security tasks, often stemming from administrative controls.
Administrative Control
Security controls implemented through policies, procedures, guidelines, and training to manage security risks.
- Focuses on people and processes.
- Examples include security policies, incident response plans, and security awareness training.
- Forms the foundation for technical and physical controls.
Memory trick: Think of security controls like a house: Administrative is the blueprints, Technical is the alarm system, Physical is the locks and fences.