ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A company is reviewing its security controls. They have implemented a policy that states all employees must complete mandatory security awareness training annually. This control aims to educate employees about cyber threats and best practices. Which type of security control does this represent?
- AAdministrative control
- BTechnical control
- CPhysical control
- DOperational control
Show answer & explanationAnswer & explanation
Correct answer: A. Administrative control
Administrative controls are policies, procedures, guidelines, and training that govern the behavior of people and the operation of systems. Mandatory security awareness training falls directly into this category as it manages human behavior through education.
Why the other options are wrong
- B. Technical controls are software or hardware mechanisms (e.g., firewalls, encryption), not training.
- C. Physical controls protect physical assets (e.g., locks, fences), unrelated to training.
- D. Operational controls are specific to daily operations and procedures, often guided by administrative controls, but 'training' itself is an administrative control.
Administrative Control
Security controls that are implemented through policies, procedures, guidelines, and training to manage security. They govern how people behave and how systems operate within an organization.
- Focus on human behavior and organizational processes
- Examples: security policies, awareness training, screening procedures
- Often define the 'what' and 'why' of security
Memory trick: Controls are either TAP: Technical, Administrative, or Physical.