EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewMedium
A company has implemented a robust security policy that mandates frequent password changes, multi-factor authentication for all critical systems, and regular security awareness training for employees. Despite these measures, a recent internal audit revealed several instances of unauthorized access to sensitive data, primarily due to employees sharing credentials or writing them down. Which security control category is most directly failing in this scenario?
- AOperational Controls
- BManagement Controls
- CTechnical Controls
- DPhysical Controls
Show answer & explanationAnswer & explanation
Correct answer: A. Operational Controls
Operational controls are mechanisms or procedures primarily executed by people, such as security awareness training, incident response, and vulnerability management. While policies (management controls) are in place, the failure lies in the execution and adherence by employees, which falls under operational controls.
Why the other options are wrong
- B. Management controls are policies and guidelines; the policy itself is robust, but its execution is the problem.
- C. Technical controls are hardware or software-based (e.g., firewalls, MFA), which are stated as implemented.
- D. Physical controls relate to securing the physical environment (e.g., locks, cameras), which is not the issue here.
Operational Controls
Security controls implemented and executed by people to enforce policies and procedures, ensuring the day-to-day security of systems and data.
- Focus on human processes and procedures.
- Examples: security awareness, incident response, vulnerability management.
- Ensures policies are put into practice.
- Often involve training and monitoring.
Memory trick: TOM Puts Security In Order: Technical, Operational, Management, Physical.