A security analyst receives a governance policy that mandates weekly vulnerability scans of all production subnets and requires critical vulnerabilities to be remediated within seven days. The policy is approved by senior management and communicated to operations teams. How should the analyst classify this governance policy?
Select an answer to reveal the explanation.
Short Explanation
Think of a policy like the rulebook you hand your team, not the scanner that runs the job. It’s administrative because it tells people what to do and when, even if the scan itself is detective. The trap is naming the activity instead of the control type doing the governing.
Full Explanation
Administrative controls are governance artifacts such as policies, standards, procedures, baselines, and service-level agreements that direct human behavior, assign responsibility, and define acceptable operational practice. In vulnerability management, a mandate requiring scheduled scans and remediation timelines establishes accountability, prioritization expectations, and escalation paths, so it supports the program through documented governance rather than through automated enforcement. A detective technical control is wrong because scanning activity detects weaknesses, but the governing document itself does not inspect systems or generate findings. A preventive technical control is wrong because prevention would block or reduce exposure through mechanisms such as segmentation, patch automation, hardening baselines, or application controls, not a policy statement. A corrective operational control is wrong because remediation actions restore or improve security after a finding, whereas the policy merely sets the corrective requirement and timeline. Exam caveat: CompTIA often asks for the control category of the artifact, not the activity it describes. Operational check: map the policy clause to an asset owner, scan schedule, remediation SLA, and exception approval workflow in the vulnerability management program.