Systems Security Certified Practitioner – SSCP – Question0634

A business continuity plan is an example of which of the following?

A.
Corrective control
B. Detective control
C. Preventive control
D. Compensating control

Correct Answer: A

Explanation:

Business Continuity Plans are designed to minimize the damage done by the event, and facilitate rapid restoration of the organization to its full operational capacity. They are for use “after the fact”, thus are examples of corrective controls.
Reference(s) used for this question: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 8: Business Continuity Planning and Disaster Recovery Planning (page 273). and Conrad, Eric; Misenar, Seth; Feldman, Joshua (2012-09-01). CISSP Study Guide (Kindle Location 8069). Elsevier Science (reference). Kindle Edition. and