Question: In Chapter 7, we discussed the differences between preventive, detective, and corrective controls. Chapters 8-10 offer specific types of controls within those categories over information
In Chapter 7, we discussed the differences between preventive, detective, and corrective controls. Chapters 8-10 offer specific types of controls within those categories over information security, confidentiality, privacy, processing integrity, and availability.
Think about controls that you have encountered in your own life (personal, professional, within organizational memberships, etc.). Note that at the time, you may or may not have realized that the answer to why is this done? was that a control was being implemented: a control over operations, reporting, and/or compliance.
- Provide a specific example of a preventive control that you have encountered. Describe what it was and its purpose (i.e., describe the specific organizational objective within one of the three categories that it was implemented to protect note the category and describe in the context of the situation). As part of the description, note whether it was a control over information security, confidentiality, privacy, processing integrity, availability and/or something else. Explain.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
