Business continuity and disaster recovery fall under which category of security control?
A.
Preventive
B.
Detective
C.
Corrective
D.
Compensating
Explanation:
Business continuity and disaster recovery do not contribute directly
to organizational security, but they can serve to compensate for security disasters
by reducing the time it takes to respond to a security incident that interrupts
business productivity.
its corrective.
http://www.anao.gov.au/uploads/documents/Business_Continuity_Management.pdf
not compensating–>example IPS for open ports.
Dear Admin,
It should be
C.Corrective
Agreed with you.
Many thanks.