ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementMedium

A critical infrastructure organization relies on a Supervisory Control and Data Acquisition (SCADA) system for managing its operations. To protect the system from unauthorized access and potential cyberattacks, the organization implements network segmentation, intrusion detection systems (IDS), and strong authentication protocols. These measures are examples of what type of security control?

  1. APhysical Controls
  2. BTechnical Controls
  3. CAdministrative Controls
  4. DCompensating Controls
Show answer & explanation

Correct answer: B. Technical Controls

Network segmentation, intrusion detection systems, and strong authentication protocols are all implemented through hardware, software, or firmware. These are direct technological safeguards, classifying them as technical controls.

Why the other options are wrong

  • A. Physical controls are tangible measures to protect physical access (e.g., fences, guards, locks).
  • C. Administrative controls are policies, procedures, and guidelines (e.g., security awareness training).
  • D. Compensating controls are alternative controls used when a primary control cannot be implemented or is impractical.

Technical Controls

Security safeguards implemented through hardware, software, or firmware to protect systems and information. They are often automated and enforce security policies directly.

  • Implemented via technology (e.g., firewalls, IDS, encryption, access control lists).
  • Enforce logical security policies.
  • Often work in conjunction with administrative and physical controls.

Memory trick: Controls are A-P-T: Admin (rules), Physical (stuff), Technical (code).

More Security and Risk Management questions