nerdexam
(ISC)2

CGRC · Question #99

The security controls for an information system that are primarily implemented and executed by the information system through mechanisms contained in the hardware, software, and firmware components…

The correct answer is C. Technical controls. Security controls primarily implemented and executed by an information system through its hardware, software, and firmware components are known as technical controls.

Implementation of Security and Privacy Controls

Question

The security controls for an information system that are primarily implemented and executed by the information system through mechanisms contained in the hardware, software, and firmware components of the system are known as Response:

Options

  • AOperational controls
  • BPhysical controls
  • CTechnical controls
  • DManagement controls

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    3% (1)
  • C
    86% (25)
  • D
    3% (1)

Why each option

Security controls primarily implemented and executed by an information system through its hardware, software, and firmware components are known as technical controls.

AOperational controls

Operational controls are primarily implemented and executed by people, focusing on the day-to-day operations of security, such as security awareness training or incident response procedures.

BPhysical controls

Physical controls are tangible measures used to protect physical assets, such as fences, locks, guards, and surveillance cameras, rather than controls embedded within the system's components.

CTechnical controlsCorrect

Technical controls are security measures that are integrated into and executed by the information system itself, utilizing mechanisms within its hardware, software, and firmware. Examples include access control lists, encryption, firewalls, and intrusion detection systems, which directly enforce security policies through technology.

DManagement controls

Management controls are policies, procedures, and guidelines established by management to govern the overall security program, like risk assessments and security planning.

Concept tested: Types of security controls (Technical)

Source: https://csrc.nist.gov/glossary/term/technical-control

Topics

#Security controls#Technical controls#Control types#Information system security

Community Discussion

No community discussion yet for this question.

Full CGRC Practice