CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium
During a quarterly risk committee meeting, the CISO presents a report indicating that despite implementing a new firewall and intrusion prevention system, the organization's exposure to external cyber threats remains high, primarily due to unpatched legacy applications. The committee decides to allocate additional budget to accelerate the patching cycle for these applications. What type of control is accelerating the patching cycle primarily considered?
- ACorrective Control
- BDetective Control
- CCompensating Control
- DPreventive Control
Show answer & explanationAnswer & explanation
Correct answer: D. Preventive Control
Accelerating the patching cycle is a proactive measure designed to prevent vulnerabilities from being exploited, thereby reducing the likelihood of a successful cyberattack. This makes it a preventive control.
Why the other options are wrong
- A. Corrective controls are designed to fix issues that have already occurred or been detected.
- B. Detective controls are designed to identify and alert about events that have already occurred or are occurring.
- C. Compensating controls are alternative controls that achieve the same objective when primary controls are not feasible.
Preventive Control
A type of control designed to prevent errors, omissions, or security incidents from occurring.
- Acts proactively before an event happens.
- Examples include firewalls, access controls, and security awareness training.
- Aims to reduce the likelihood of a negative event.
Memory trick: Preventive: Protects BEFORE harm.