CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingEasy

A large pharmaceutical company is developing a new drug. The project involves significant regulatory compliance requirements and intellectual property (IP) protection. The risk practitioner is tasked with designing controls for the research and development (R&D) phase. To prevent unauthorized access to sensitive research data and ensure regulatory adherence, the practitioner recommends implementing strict role-based access controls (RBAC), mandatory data encryption for all R&D data, and regular training on data handling policies. These controls are primarily examples of which of the following?

  1. APreventive controls.
  2. BDetective controls.
  3. CCompensating controls.
  4. DCorrective controls.
Show answer & explanation

Correct answer: A. Preventive controls.

Role-based access controls, mandatory data encryption, and regular training are all designed to stop unauthorized access or policy violations from occurring in the first place. These are classic examples of preventive controls.

Why the other options are wrong

  • B. Detective controls would identify unauthorized access or policy violations after they have occurred (e.g., audit logs, intrusion detection alerts).
  • C. Compensating controls are implemented when a primary control is not feasible or effective, but these are direct, primary controls.
  • D. Corrective controls would fix the situation after an incident (e.g., incident response plan, data recovery).

Preventive Controls

Controls designed to stop undesirable events from happening in the first place, thereby reducing the likelihood of a risk event occurring.

  • Aimed at preventing errors, omissions, or malicious acts.
  • Operate before a risk event can materialize.
  • Examples include access controls, encryption, and training.

Memory trick: Prevent Before, Detect During, Correct After.

More Risk Response and Reporting questions