nerdexam
Isaca

CISA · Question #19

Following the sale of a business division, employees will be transferred to a new organization, but they will retain access to IT equipment from the previous employer. An IS auditor has recommended th

The correct answer is D. Directive control. The recommendation for both organizations to agree to and document an acceptable use policy for shared IT equipment is a directive control. It establishes clear guidelines and expectations for appropriate usage.

Submitted by paula_co· Apr 18, 2026Governance and Management of IT

Question

Following the sale of a business division, employees will be transferred to a new organization, but they will retain access to IT equipment from the previous employer. An IS auditor has recommended that both organizations agree to and document an acceptable use policy for the equipment. What type of control has been recommended?

Options

  • ACorrective control
  • BPreventive control
  • CDetective control
  • DDirective control

How the community answered

(31 responses)
  • B
    3% (1)
  • C
    6% (2)
  • D
    90% (28)

Why each option

The recommendation for both organizations to agree to and document an acceptable use policy for shared IT equipment is a directive control. It establishes clear guidelines and expectations for appropriate usage.

ACorrective control

A corrective control remedies an incident or problem after it has occurred (e.g., restoring systems), which is not the purpose of an acceptable use policy.

BPreventive control

While an AUP aims to prevent misuse, it does so by guidance rather than technical enforcement; a preventive control directly blocks or stops an action from occurring (e.g., a firewall).

CDetective control

A detective control identifies an event after it has occurred (e.g., audit logging, intrusion detection), whereas an AUP defines acceptable behavior beforehand.

DDirective controlCorrect

A directive control sets forth rules, policies, and guidelines that dictate how individuals or systems should operate or behave. An acceptable use policy (AUP) precisely defines the permissible and prohibited actions regarding the use of IT equipment, thereby guiding employees' behavior and ensuring compliance with organizational expectations, making it a classic example of a directive control.

Concept tested: Types of security controls (Directive)

Source: https://learn.microsoft.com/en-us/compliance/regulatory/auditing-security-controls

Topics

#Control types#Directive controls#Acceptable Use Policy (AUP)#IT Governance

Community Discussion

No community discussion yet for this question.

Full CISA Practice