Which of the following best describes the primary purpose of directive controls in a security context?
To detect and respond to security incidents after they occur
To provide guidance and instructions on maintaining security
To discourage potential attackers from targeting the organization
To implement and manage security technologies