CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium
A retail company is planning to launch a new e-commerce website. The project team is considering various security controls. They decide to implement a Web Application Firewall (WAF) to protect against common web-based attacks like SQL injection and cross-site scripting (XSS). This implementation is an example of which type of security control?
- ADetective
- BCorrective
- CCompensating
- DPreventive
Show answer & explanationAnswer & explanation
Correct answer: D. Preventive
A Web Application Firewall (WAF) is designed to actively block or prevent attacks like SQL injection and XSS from reaching the web application. Therefore, it is a preventive control.
Why the other options are wrong
- A. Detective controls identify incidents after they have occurred (e.g., intrusion detection systems).
- B. Corrective controls fix issues after an incident (e.g., patching vulnerabilities).
- C. Compensating controls are alternative controls used when a primary control cannot be implemented.
Preventive Control
A security control designed to stop an undesirable event from occurring.
- Acts before an incident happens.
- Aims to reduce likelihood of risk.
- Examples include firewalls, access controls, encryption.
Memory trick: Prevent, Detect, Correct, Compensate.