ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementMedium
A critical infrastructure organization relies on a Supervisory Control and Data Acquisition (SCADA) system for managing its operations. To protect the system from unauthorized access and potential cyberattacks, the organization implements network segmentation, intrusion detection systems (IDS), and strong authentication protocols. These measures are examples of what type of security control?
- APhysical Controls
- BTechnical Controls
- CAdministrative Controls
- DCompensating Controls
Show answer & explanationAnswer & explanation
Correct answer: B. Technical Controls
Network segmentation, intrusion detection systems, and strong authentication protocols are all implemented through hardware, software, or firmware. These are direct technological safeguards, classifying them as technical controls.
Why the other options are wrong
- A. Physical controls are tangible measures to protect physical access (e.g., fences, guards, locks).
- C. Administrative controls are policies, procedures, and guidelines (e.g., security awareness training).
- D. Compensating controls are alternative controls used when a primary control cannot be implemented or is impractical.
Technical Controls
Security safeguards implemented through hardware, software, or firmware to protect systems and information. They are often automated and enforce security policies directly.
- Implemented via technology (e.g., firewalls, IDS, encryption, access control lists).
- Enforce logical security policies.
- Often work in conjunction with administrative and physical controls.
Memory trick: Controls are A-P-T: Admin (rules), Physical (stuff), Technical (code).