Which concept is described as managing personnel and assets through security policies, standards, procedures, guidelines, and baselines?

Get ready for the CompTIA SecurityX exam! Study with multiple choice questions, each crafted to enhance understanding and confidence for your certification journey. Successfully navigate every section to achieve your goal!

Multiple Choice

Which concept is described as managing personnel and assets through security policies, standards, procedures, guidelines, and baselines?

Explanation:
Administrative controls focus on governance and management of security. They’re the rules and frameworks that shape how people and assets are handled, expressed through policies, standards, procedures, guidelines, and baselines. This approach sets the expectations for behavior, roles, access, training, asset handling, and risk management across the organization, rather than implementing a technical or physical safeguard directly. An asset is simply a resource to protect, an access control list is a specific technical mechanism for permissions, and advisory policies describe guidance rather than the full, enforceable governance structure described here. So the description best fits administrative controls.

Administrative controls focus on governance and management of security. They’re the rules and frameworks that shape how people and assets are handled, expressed through policies, standards, procedures, guidelines, and baselines. This approach sets the expectations for behavior, roles, access, training, asset handling, and risk management across the organization, rather than implementing a technical or physical safeguard directly. An asset is simply a resource to protect, an access control list is a specific technical mechanism for permissions, and advisory policies describe guidance rather than the full, enforceable governance structure described here. So the description best fits administrative controls.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy