A company implements a mandatory security awareness training program for all employees to combat threats like phishing and social engineering. This type of training is an example of which security control type?
Preventive controls are designed to stop an incident before it can happen. Security awareness training is considered a preventive control because its primary purpose is to educate employees on how to recognize and avoid security threats, thereby preventing security incidents from occurring. While it also directs behavior, its main function in this context is prevention.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are preventive security controls?
Open an interactive chat with Bash
Why is employee training considered a preventive control?