An organization implements a set of policies that outline employee responsibilities and expected behaviors regarding information security. What type of security control is this an example of?
Policies that outline employee responsibilities and expected behaviors are examples of directive controls. Directive controls are designed to guide or instruct individuals or systems to ensure compliance with security requirements. They establish guidelines and expectations to influence behavior. Detective controls are intended to identify and detect unwanted events or incidents after they occur. Corrective controls focus on minimizing the impact of a security incident after it has occurred. Preventive controls aim to stop unwanted events from happening in the first place.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are examples of directive controls?
Open an interactive chat with Bash
How do directive controls differ from preventive controls?
Open an interactive chat with Bash
Can you provide an example of a detective control?