ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingEasy

A security auditor is reviewing an organization's access control policies and procedures. During the review, the auditor discovers that several former employees still have active accounts on critical systems. Which type of security control failure does this scenario primarily represent?

  1. ATechnical control failure
  2. BCompensating control failure
  3. CPhysical control failure
  4. DAdministrative control failure
Show answer & explanation

Correct answer: D. Administrative control failure

The scenario describes a failure in managing user accounts and policies, which falls under administrative controls. Technical controls are automated safeguards, physical controls relate to environmental protection, and compensating controls mitigate risks when primary controls are not feasible.

Why the other options are wrong

  • A. Technical controls are automated safeguards (e.g., firewalls, encryption).
  • B. Compensating controls are alternative measures when primary controls are not adequate or feasible.
  • C. Physical controls protect the physical environment (e.g., locks, guards, cameras).

Administrative Controls

Administrative controls are security safeguards implemented through policies, procedures, guidelines, and training to manage how an organization protects its assets.

  • Focus on human behavior and organizational processes.
  • Examples include access control policies, security awareness training, incident response plans, and hiring procedures.
  • Often define the 'what' and 'how' for other control types.

Memory trick: TAP, as in 'Tap into security with Technical, Administrative, and Physical controls!'

More Security Assessment and Testing questions