CGRC · Question #28
The security controls for an information system that primarily are implemented by people (as opposed to systems) are known as Response:
The correct answer is B. Operational controls. Security controls primarily implemented by people, focusing on the day-to-day operations and procedures, are known as operational controls. These controls involve human actions and adherence to established security practices.
Question
The security controls for an information system that primarily are implemented by people (as opposed to systems) are known as Response:
Options
- AManagement controls
- BOperational controls
- CTechnical controls
- DLogical controls
How the community answered
(19 responses)- B84% (16)
- C11% (2)
- D5% (1)
Why each option
Security controls primarily implemented by people, focusing on the day-to-day operations and procedures, are known as operational controls. These controls involve human actions and adherence to established security practices.
Management controls are strategic and governance-focused, involving risk management, security planning, and oversight, rather than direct human execution of day-to-day security tasks.
Operational controls are security measures executed primarily by personnel, focusing on the daily activities, procedures, and practices that ensure the secure operation of an information system. These include security awareness, incident handling, and administrative policies that rely on human implementation.
Technical controls are hardware, software, or firmware-based security mechanisms that automate protection, rather than relying on human implementation.
Logical controls are often a subset of technical controls, using software and data-based access restrictions and encryption to protect information.
Concept tested: Types of Security Controls - Operational
Source: https://csrc.nist.gov/glossary/term/operational_controls
Topics
Community Discussion
No community discussion yet for this question.