CAS-002 · Question #713
A newly-hired Chief Information Security Officer (CISO) is faced with improving security for a company with low morale and numerous disgruntled employees. After reviewing the situation for several…
The correct answer is B. An employee remotely configuring the email server at a relative's company during work. Technical controls are system-enforced mechanisms such as firewall rules and access controls that can restrict unauthorized computer-based actions performed on or through company infrastructure.
Question
A newly-hired Chief Information Security Officer (CISO) is faced with improving security for a company with low morale and numerous disgruntled employees. After reviewing the situation for several weeks the CISO publishes a more comprehensive security policy with associated standards. Which of the following issues could be addressed through the use of technical controls specified in the new security policy?
Options
- AEmployees publishing negative information and stories about company management on
- BAn employee remotely configuring the email server at a relative's company during work
- CEmployees posting negative comments about the company from personal phones and
- DExternal parties cloning some of the company's externally facing web pages and creating
How the community answered
(17 responses)- A12% (2)
- B76% (13)
- C6% (1)
- D6% (1)
Why each option
Technical controls are system-enforced mechanisms such as firewall rules and access controls that can restrict unauthorized computer-based actions performed on or through company infrastructure.
Employees posting on external social media from company or personal devices involves expressive personal behavior that internal technical controls cannot fully block without also restricting legitimate business use of the same platforms.
An employee remotely configuring an external mail server using company systems during work hours can be blocked through technical controls such as outbound firewall rules restricting remote administration protocols like SSH, RDP, or SMTP management ports, as well as network-level data loss prevention policies. These controls are enforced automatically by the system and do not rely on the employee's willingness to comply, making them effective even in a low-morale environment. The new security policy can mandate these controls at the network perimeter or endpoint level.
Negative comments posted from employees' personal phones over personal networks fall entirely outside the reach of company-enforced technical controls, as the company has no jurisdiction over personal devices or connections.
Web page cloning is performed by external parties on infrastructure entirely outside the company's network perimeter, making internal technical controls powerless to prevent it.
Concept tested: Applicability of technical security controls to insider threat activities
Source: https://csrc.nist.gov/glossary/term/technical_controls
Topics
Community Discussion
No community discussion yet for this question.