CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingEasy
A healthcare organization is subject to strict data privacy regulations, including HIPAA. The risk management team is documenting controls for its electronic health record (EHR) system. They have identified a control requiring all patient data access to be logged and reviewed weekly for suspicious activity. Which of the following is the MOST appropriate classification for this control in terms of its timing?
- ADetective
- BPreventive
- CCorrective
- DDirective
Show answer & explanationAnswer & explanation
Correct answer: A. Detective
A control that logs and reviews activity after it has occurred, specifically for 'suspicious activity,' is classified as a detective control. It's designed to identify anomalies or policy violations after they have already happened, allowing for subsequent investigation and corrective action. It does not prevent the initial access or activity.
Why the other options are wrong
- B. Preventive controls stop an event from happening in the first place.
- C. Corrective controls fix issues or restore systems after an event has been detected.
- D. Directive controls are policies or guidelines that mandate actions (e.g., 'all staff must use strong passwords') but are not a functional control type in this context.
Detective Controls
Controls designed to identify and flag undesirable events or deviations after they have occurred.
- Focus on discovery rather than prevention.
- Examples include audit logs, intrusion detection systems, and reconciliation.
- Essential for identifying breaches, errors, or policy violations.
Memory trick: Prevent Before, Detect During, Correct After.