Administrative Controls: Policies and procedures implemented by an organization to manage and regulate user behavior and system operation. These include security policies, operating procedures, rules of behavior, and personnel controls, among others. Administrative controls are a vital part of an organization’s overall security strategy, serving to guide the appropriate use and handling of resources, define roles and responsibilities, and establish processes for monitoring, incident response, and recovery. They complement technical and physical controls to create a multi-layered defense against security threats.
Categories: CC D1: Security Principles | CCSP D6: Legal - Risk and Compliance | CISM D3: Information Security Program | CISSP D5: Identity and Access Management (IAM) | Security+ D5: Security Program Management and Oversight | SSCP D1: Security Concepts and Practices
Related Articles: