Certified Information Systems Security Professional CISSP · Free Practice Question Medium

Question 123

You are the newly appointed Chief Information Security Officer (CISO) for a global corporation with operations in several countries. You have a mandate to overhaul the company's existing IT security framework due to recent security breaches. You are planning to apply different types of security controls based on the operational requirements of different divisions within the organization. Which type of security control would be most effective in compensating for an inability to apply standard security controls due to the unique needs of a specific division within the organization?
  • A Applying compensating controls that provide an equivalent level of protection.
  • B Implementing a stringent password policy company-wide.
  • C Hiring additional security personnel for physical control at the specific division's location.
  • D Installing a state-of-the-art Intrusion Detection System (IDS) for the specific division.
Reveal correct answer

Correct answer: A

Explanation

The correct answer: Compensating controls are designed to provide an alternative solution when primary security controls cannot be applied due to operational, financial, or other constraints. In this situation, given the unique needs of a specific division, the most appropriate solution would be to apply compensating controls that could fulfill the same security function or goal as the primary controls, maintaining an equivalent level of protection. The incorrect answers: Installing an Intrusion Detection System (IDS) is an important measure for detecting potential intrusions, but it is primarily a detective control rather than a compensating one. Although useful, an IDS is not specifically tailored to address unique security requirements that might prevent the use of standard controls in certain situations. Implementing a stringent password policy is a form of preventive control that can enhance security across the entire company. This is a good practice, but it does not directly address the issue of compensating for an inability to apply standard security controls in a specific division. Hiring additional security personnel for physical control can enhance security, but it is a physical control type. Similar to installing a state-of-the-art Intrusion Detection System (IDS) and implementing a stringent password policy, it does not serve as a compensating control for specific circumstances that prohibit the use of standard controls. Additionally, physical control might not be the most effective solution for a division with unique IT-related security needs.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need