CGRC · Question #27
The security control type for an information system that primarily are implemented and executed by people (as opposed to systems). Response:
The correct answer is A. Operational. Operational security controls are primarily implemented and executed by people within an organization, focusing on the day-to-day security activities and procedures. These controls rely on human actions and adherence to policies.
Question
The security control type for an information system that primarily are implemented and executed by people (as opposed to systems). Response:
Options
- AOperational
- BTechnical
- COrganizational
- DImplementation
How the community answered
(67 responses)- A94% (63)
- B1% (1)
- C1% (1)
- D3% (2)
Why each option
Operational security controls are primarily implemented and executed by people within an organization, focusing on the day-to-day security activities and procedures. These controls rely on human actions and adherence to policies.
Operational controls are security measures that are primarily implemented and executed by individuals, encompassing policies, procedures, and practices related to the daily operation of information systems. Examples include security awareness training, incident response procedures, and physical security measures that require human involvement.
Technical controls are security safeguards that are integrated into information systems through hardware, software, or firmware.
Organizational controls are management-oriented safeguards focused on the overall structure and governance of an organization's security program, often broader than just human-implemented operational activities.
Implementation is a phase or characteristic of how controls are put into practice, not a distinct control type based on who or what implements them.
Concept tested: Types of Security Controls - Operational
Source: https://csrc.nist.gov/glossary/term/operational_controls
Topics
Community Discussion
No community discussion yet for this question.