QuestionQ34

Security Program Management and Oversight

An organization faces a new regulatory requirement to implement corrective controls on a financial system. Which of the following is the most likely reason for this new requirement?

Explanation

Corrective controls remediate errors or incidents and limit their downstream impact. Ensuring errors do not propagate to other systems is therefore a corrective-control objective; preventing unauthorized changes is a preventive-control objective, and purchasing insurance is risk transfer.

Community Discussion

No comments yet. Be the first to start the discussion!