CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityHard
An organization is conducting a post-incident review after a significant data breach. The review team identifies that while technical controls (firewalls, IDS) were in place, human error (a click on a phishing link) was the root cause, and the security awareness training program was outdated and ineffective. Based on this finding, the organization should prioritize updating and enhancing its security awareness training program. This action represents an improvement in which type of control?
- ACompensating Control
- BPhysical Control
- CAdministrative Control
- DTechnical Control
Show answer & explanationAnswer & explanation
Correct answer: C. Administrative Control
Security awareness training is a policy, procedure, or guideline designed to manage human behavior and organizational processes. These types of controls fall under administrative controls.
Why the other options are wrong
- A. Compensating controls are alternatives when primary controls are not feasible, which is not the case here.
- B. Physical controls protect physical assets (e.g., locks, guards).
- D. Technical controls are hardware or software mechanisms (e.g., firewalls, IDS).
Administrative Control
Security controls implemented through policies, procedures, guidelines, and training to manage human behavior and organizational processes related to security.
- Focuses on people and processes.
- Examples: security policies, awareness training, incident response plans.
- Often complements technical and physical controls.
Memory trick: Admin, Technical, Physical are the main control types.