
Management controls, whether administrative, procedural or technical, are the
mechanisms and techniques instituted to implement a security policy. Some controls
are explicitly concerned with protecting information and information systems, but the
concept of management controls includes much more than a computer’s specific role
in enforcing security.
Controls have 3 functions:
Prevent the unauthorized disclosure, modification or destruction of information.
Detect the unauthorized disclosure, modification or destruction of information.
Correct the unauthorized disclosure, modification or destruction of information.
Controls should be required for:
Physical ...