CISA · Question #19
Following the sale of a business division, employees will be transferred to a new organization, but they will retain access to IT equipment from the previous employer. An IS auditor has recommended th
The correct answer is D. Directive control. The recommendation for both organizations to agree to and document an acceptable use policy for shared IT equipment is a directive control. It establishes clear guidelines and expectations for appropriate usage.
Question
Following the sale of a business division, employees will be transferred to a new organization, but they will retain access to IT equipment from the previous employer. An IS auditor has recommended that both organizations agree to and document an acceptable use policy for the equipment. What type of control has been recommended?
Options
- ACorrective control
- BPreventive control
- CDetective control
- DDirective control
How the community answered
(31 responses)- B3% (1)
- C6% (2)
- D90% (28)
Why each option
The recommendation for both organizations to agree to and document an acceptable use policy for shared IT equipment is a directive control. It establishes clear guidelines and expectations for appropriate usage.
A corrective control remedies an incident or problem after it has occurred (e.g., restoring systems), which is not the purpose of an acceptable use policy.
While an AUP aims to prevent misuse, it does so by guidance rather than technical enforcement; a preventive control directly blocks or stops an action from occurring (e.g., a firewall).
A detective control identifies an event after it has occurred (e.g., audit logging, intrusion detection), whereas an AUP defines acceptable behavior beforehand.
A directive control sets forth rules, policies, and guidelines that dictate how individuals or systems should operate or behave. An acceptable use policy (AUP) precisely defines the permissible and prohibited actions regarding the use of IT equipment, thereby guiding employees' behavior and ensuring compliance with organizational expectations, making it a classic example of a directive control.
Concept tested: Types of security controls (Directive)
Source: https://learn.microsoft.com/en-us/compliance/regulatory/auditing-security-controls
Topics
Community Discussion
No community discussion yet for this question.