What Control Type Is Implemented by Security Baseline Policies?

Control Types / Security Governance
Answer Correct answer: B — Enforcing minimum security control baselines through a formal policy establishes a directive control that mandates compliant server configurations.

An organization has implemented a policy to require minimum security control baselines when configuring servers or systems. What control type has been implemented?

  1. Compensating
  2. Directive Correct Answer
  3. Preventive
  4. Corrective

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between directive controls (policies/guidelines) and preventive controls (technical safeguards), with the trap being confusion over the policy requirement versus the technical prevention it enables.

This CISA question tests the classification of security controls based on organizational policies. It establishes that mandating minimum security baselines through a formal policy constitutes a directive control.

Many candidates incorrectly select Preventive because baselines reduce risk, but they overlook that the implemented mechanism here is a mandatory policy, which defines it as directive.

Community Discussion (4 comments)

46080f2 👍 1 Selected: B
A directive control is a type of control that establishes policies, procedures, and guidelines to direct the behavior of individuals within an organization. In this case, the implementation of a policy requiring minimum security control baselines for configuring servers or systems falls under directive controls as it sets the expectations and requirements for security practices within the organization. This conclusion is supported by the understanding that directive controls are designed to guide actions and decisions, which aligns with the nature of establishing security policies.
pLulu 👍 1
C. Preventive. Preventive controls are designed to prevent security incidents by establishing standards and baselines that must be followed. By requiring minimum security control baselines when configuring servers or systems, the organization is proactively reducing the risk of security vulnerabilities and ensuring that systems are configured securely from the outset. Option B, "Directive," refers to controls that provide guidance or instructions on how to act. While requiring minimum security control baselines does provide guidance, the primary purpose of this policy is to prevent security incidents by ensuring that systems are configured securely from the start. Therefore, it is best categorized as a preventive control. Directive controls are more about setting policies, procedures, and guidelines to direct behaviour, whereas preventive controls are specifically aimed at stopping unwanted events from occurring.
Enig 👍 2
B. Directive A directive control is one that sets policies or guidelines that direct behavior, ensuring that certain actions or standards are followed. In this case, the policy to require minimum security control baselines when configuring servers or systems is a directive control because it establishes mandatory security configurations that must be followed.
blehbleh 👍 1 Selected: B
this is b

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Directive controls are designed to direct or guide individual behavior through formal policies, standards, and guidelines. By implementing a policy that requires minimum security control baselines, the organization is establishing mandatory expectations that dictate how servers must be configured. ISACA classifies any control primarily communicated through written mandates or procedural requirements as directive.

Why the Other Options Are Wrong

Compensating controls act as alternative safeguards when primary controls are impractical or unavailable, which does not apply here. Corrective controls focus on restoring systems and data after a security incident occurs, rather than setting pre-implementation standards. Preventive controls utilize active technical mechanisms like firewalls or encryption to stop threats, whereas this scenario specifically highlights a policy mandate rather than a technical barrier.

Community Comment Notes

One candidate argued that baselines proactively reduce vulnerabilities, but overlooked that the implemented artifact is a policy mandate rather than a technical barrier. Another noted that directives "establish expectations and requirements for security practices," which accurately matches the scenario. The majority correctly identified the control type by focusing on the word "policy" as the defining implementation method.

Exam Strategy

When scanning CISA questions for control classifications, immediately flag keywords like "policy," "standard," "guideline," and "procedure." These terms consistently point to directive controls, regardless of whether the underlying measure eventually prevents or detects an incident.

Frequently Asked Questions

Why isn't a security baseline considered a preventive control?

Baselines are technical standards, but when implemented via a mandatory policy, the control type becomes directive. Preventive controls rely on active technical mechanisms like firewalls.

How does ISACA distinguish directive from compensating controls?

Directive controls set mandatory rules and baselines to guide behavior, while compensating controls substitute for missing primary controls. CISA focuses on policy mandates versus technical workarounds.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide