Systems Security Certified Practitioner – SSCP – Question0146

Which of the following is NOT a compensating measure for access violations?

A.
Backups
B. Business continuity planning
C. Insurance
D. Security awareness

Correct Answer: D

Explanation:

Security awareness is a preventive measure, not a compensating measure for access violations. Source: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 2: Access control systems (page 50).