A security administrator performs a weekly audit of firewall rules and user permissions on network shares. This proactive, hands-on review process is an example of which category of security control?
The correct answer is operational control. Operational controls are security measures implemented and managed by people in their day-to-day work. The act of an administrator regularly reviewing firewall rules and user permissions is a human-centric process focused on maintaining security, which is the definition of an operational control. Technical controls are the technologies themselves, like the firewall or the access control list system. Managerial controls are the high-level policies and procedures, such as a policy that mandates weekly reviews. Physical controls are tangible measures like fences or locks.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are operational controls in cybersecurity?
Open an interactive chat with Bash
How are operational controls different from technical controls?
Open an interactive chat with Bash
Why are operational controls important in cybersecurity?