Which type of security control focuses on people and processes rather than technology?

Study for the CCST Cybersecurity Test. Study with flashcards and multiple choice questions, each question has hints and explanations. Get ready for your exam!

Multiple Choice

Which type of security control focuses on people and processes rather than technology?

Explanation:
Administrative controls are the ones that shape behavior and the way work gets done. They focus on people and processes rather than on technology. Examples include security policies and procedures, training and awareness programs, change management, incident response plans, access governance, and separation of duties. These controls aim to reduce risk by guiding how tasks are performed and decisions are made, rather than by technology enforcing security. In contrast, technical controls rely on hardware or software to enforce security (like firewalls or encryption), physical controls protect facilities and equipment (like badges or locks), and detective controls focus on identifying incidents after they occur (like logs and audits).

Administrative controls are the ones that shape behavior and the way work gets done. They focus on people and processes rather than on technology. Examples include security policies and procedures, training and awareness programs, change management, incident response plans, access governance, and separation of duties. These controls aim to reduce risk by guiding how tasks are performed and decisions are made, rather than by technology enforcing security.

In contrast, technical controls rely on hardware or software to enforce security (like firewalls or encryption), physical controls protect facilities and equipment (like badges or locks), and detective controls focus on identifying incidents after they occur (like logs and audits).

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy