Certified Information Systems Auditor (CISA) — Question 466

An organization is shifting to a remote workforce. In preparation, the IT department is performing stress and capacity testing of remote access infrastructure and systems. What type of control is being implemented?

Answer options

Correct answer: C

Explanation

The correct answer is C, Preventive, as the stress and capacity testing aims to identify potential issues before they impact the remote workforce. Directive controls establish policies and guidelines, Detective controls monitor for incidents after they occur, and Compensating controls provide alternative measures but do not directly address the assessment of system capacity.