Under common security-control taxonomies (e.g., NIST SP 800-53 and CompTIA), a periodic security audit that reviews system activity and policy compliance is BEST categorized as which type of control?
A security audit examines logs, configurations, and practices after activities have occurred. Its purpose is to uncover inappropriate actions, policy violations, or anomalies so the organization can investigate and respond. Because it detects events rather than preventing or discouraging them, it falls into the detective control category. Deterrent controls (such as warning signs or visible cameras) strive to discourage wrongdoing, preventive controls block actions outright, and corrective controls minimize damage after an incident.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of a detective control?
Open an interactive chat with Bash
How does a detective control differ from a preventive control?
Open an interactive chat with Bash
Can you explain more about NIST SP 800-53's role in security control categorization?