When an organization is unable to implement a security control in the baseline or when, due to the specific nature of an information system or its environment of operation, the control in the baseline is not a cost-effective means of obtaining the needed risk mitigation then the organization may employ this type of control:

🎲 Try a Random Question  |  Total Questions in Quiz: 124  |  🧠 Study this quiz with Flashcards
This question is part of a full practice quiz:
Certified Authorization Professional (CAP) — practice the complete quiz, review flashcards, or try a random question.


1. When an organization is unable to implement a security control in the baseline or when, due to the specific nature of an information system or its environment of operation, the control in the baseline is not a cost-effective means of obtaining the needed risk mitigation then the organization may employ this type of control: