Administrative Controls

Administrative Control

Prev Question Next Question

Question

Which of the following is an administrative control?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

C.

Among the given options, the administrative control is "C. Data loss prevention program."

Administrative controls are policies and procedures designed to guide human behavior and decision-making within an organization. They are an essential part of an organization's overall risk management strategy. Administrative controls include a wide range of measures such as security policies, procedures, guidelines, and training.

Option A, "Water detection" is a technical control designed to detect and prevent water damage to IT equipment. Technical controls are measures that use technology to mitigate risks, such as firewalls, encryption, and intrusion detection systems.

Option B, "Reasonableness check" is a control that verifies the accuracy and completeness of data entered into a system. This control is often used in financial systems to detect errors or fraudulent activity. However, it is not an administrative control, but rather a detective control that helps identify errors or deviations from expected behavior.

Option D, "Session timeout" is a technical control that automatically logs out users after a predetermined period of inactivity. This control helps protect sensitive data by reducing the risk of unauthorized access. Like Option A, this is also a technical control.

Option C, "Data loss prevention program" is an administrative control that aims to prevent the loss of sensitive data. It includes policies, procedures, and technologies that help organizations identify, monitor, and protect sensitive data from unauthorized access, use, disclosure, or theft. This control is designed to guide human behavior and decision-making, making it an administrative control.

In summary, option C is the correct answer because it is an administrative control that guides human behavior and decision-making, and it aims to prevent the loss of sensitive data.