An organization publishes an acceptable-use policy that outlines how employees may access and utilize company resources. Which type of security control does this policy represent?
Written policies that outline permitted or required behavior are directive controls because they provide explicit guidance to users and systems. Detective controls identify incidents, preventive controls block them from occurring, and compensating controls provide alternatives when primary controls are not feasible. Therefore, the acceptable-use policy exemplifies a directive control.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are the key components of a security policy?
Open an interactive chat with Bash
Why is employee training important for security policies?