Question

Difficulty: Very hardSecurity Control Categories and Types

An enterprise financial institution relies on a legacy mainframe system to process batch payments. A security compliance audit reveals that the mainframe application cannot natively support TLS 1.3 network transport encryption due to legacy protocol stack limitations. To satisfy data-in-transit security requirements without taking the system offline, the security engineering team deploys an inline hardware cryptographic proxy that intercepts outbound mainframe communications and encapsulates them inside an encrypted IPsec tunnel across the internal network. Which of the following best classifies the deployment of the hardware cryptographic proxy?

  1. Technical category and Compensating functional typeAnswer
  2. B
    Technical category and Preventive functional type
  3. C
    Operational category and Corrective functional type
  4. D
    Managerial category and Directive functional type

Answer

Technical category and Compensating functional type
The deployment of an inline hardware cryptographic proxy is executed via automated hardware technology, placing it firmly within the Technical (Logical) control category. Functionally, because native TLS 1.3 application encryption (the baseline primary control) cannot be implemented due to legacy system limitations, the proxy serves as an alternative control to achieve equivalent data protection. Controls implemented to satisfy a security requirement when a primary control is unfeasible are classified as Compensating controls.

Step-by-Step Solution

1
Determine the security control category
Identified as Technical category
The control consists of an inline hardware appliance executing cryptographic encapsulation routines autonomously, which falls under logical/technical mechanisms rather than human operations or administrative policies.
2
Determine the functional control type based on the operational context
Identified as Compensating functional type
The primary control requirement (native TLS 1.3 support on the legacy mainframe) is technically impossible to achieve without system replacement. Deploying an external hardware proxy satisfies the overarching security objective (protecting data in transit) as an explicit alternative mitigation.
3
Combine category and functional type classifications
Technical category + Compensating functional type
Synthesizing both dimensions yields a technical compensating control.

Key Concept

Security Control Categories and Functional Types
Rate this question