312-50V10 · Question #274
The precaution of prohibiting employees from bringing personal computing devices into a facility is what type of security control?
The correct answer is B. Procedural. Prohibiting personal devices via policy is a procedural (administrative) control because it governs employee behavior through rules rather than technology or physical barriers.
Question
The precaution of prohibiting employees from bringing personal computing devices into a facility is what type of security control?
Options
- APhysical
- BProcedural
- CTechnical
- DCompliance
How the community answered
(26 responses)- B96% (25)
- D4% (1)
Why each option
Prohibiting personal devices via policy is a procedural (administrative) control because it governs employee behavior through rules rather than technology or physical barriers.
Physical controls involve tangible, physical mechanisms such as locks, mantraps, security guards, or device scanners that physically prevent access - a policy prohibition alone has no physical enforcement component.
Procedural controls, also called administrative controls, are policies, rules, and procedures that direct human behavior to reduce risk. A prohibition enforced through a workplace policy or employee agreement is procedural in nature - its effectiveness depends on compliance with a stated rule, not on a physical object or technical mechanism.
Technical controls rely on technology implementations such as network access control (NAC), endpoint management software, or port blockers to enforce restrictions - a verbal or written policy is not a technical control.
Compliance is not a recognized category of security control in standard frameworks such as NIST SP 800-53 or ISO 27001 - it describes adherence to controls, not a control type itself.
Concept tested: Classification of administrative vs. physical vs. technical controls
Source: https://csrc.nist.gov/glossary/term/administrative_control
Topics
Community Discussion
No community discussion yet for this question.