Which term is used to force compliance with the security policy and practices within the organization?

Study for the CompTIA SecurityX Test. Equip yourself with comprehensive flashcards and multiple choice questions that include hints and explanations. Gear up for your certification exam!

Multiple Choice

Which term is used to force compliance with the security policy and practices within the organization?

Directive controls are administrative measures that mandate actions to comply with security policy. They force consistent behavior by establishing requirements, roles, and processes that people must follow—such as security policies, standards, procedures, and mandatory training. This is why they best describe forcing compliance: they set explicit expectations and consequences for noncompliance, guiding how the organization and its members should operate.

Deterrent controls aim to discourage violations through penalties or warnings but don’t compel action. Detective controls identify and reveal violations after they occur, rather than enforcing the policy in real time. Preventive controls try to stop incidents from happening in the first place, by limiting access or capabilities.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy