CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityEasy

A financial services organization is implementing a new customer relationship management (CRM) system that will store highly sensitive client data. The project team is evaluating various security controls to protect this data. Which of the following would be considered a detective control?

  1. AImplementing strong encryption for data at rest and in transit.
  2. BConducting regular security awareness training for employees handling client data.
  3. CEnforcing multi-factor authentication (MFA) for all user access.
  4. DDeploying an intrusion detection system (IDS) to monitor network traffic for suspicious activity.
Show answer & explanation

Correct answer: D. Deploying an intrusion detection system (IDS) to monitor network traffic for suspicious activity.

A detective control aims to identify and alert to an incident after it has occurred or is in progress. An Intrusion Detection System (IDS) fits this description by monitoring and flagging suspicious activities.

Why the other options are wrong

  • A. This is a preventive control, designed to stop unauthorized access before it happens.
  • B. This is a preventive control, aiming to educate users to prevent security incidents.
  • C. This is a preventive control, designed to enforce stronger authentication and prevent unauthorized access.

Detective Control

A security control designed to identify and alert to an incident after it has occurred or is in progress, allowing for a timely response.

  • Identifies incidents
  • Operates during or after an event
  • Examples: IDS, security logs, audit trails

Memory trick: Prevent, Detect, Correct: The three phases of control.

More Information Technology and Security questions