Which security control type is exemplified by organizational security policies and guidelines that direct the behavior of users and systems toward compliance?
Security policies, standards, and guidelines do not directly stop or detect attacks. Instead, they provide direction by defining required behaviors and rules. Because they set expectations and guide how people and systems should act, they are categorized as directive controls. Detective controls identify incidents after they occur, preventive controls stop incidents, and corrective controls restore normal operations.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are examples of directive controls in cybersecurity?
Open an interactive chat with Bash
How do directive controls differ from preventive controls?
Open an interactive chat with Bash
Why is it important for organizations to implement directive controls?