1. National Institute of Standards and Technology (NIST). (2017). Special Publication 800-53 Revision 5: Security and Privacy Controls for Information Systems and Organizations. Section 2.2
"Control Structure
" categorizes controls into Management
Operational
and Technical classes. The Physical and Environmental Protection (PE) family
which includes video surveillance (PE-6)
contains numerous technical implementations.
2. National Institute of Standards and Technology (NIST). (2017). Special Publication 800-12 Revision 1: An Introduction to Information Security. Section 4.2
"Security Controls
" defines technical controls as those "primarily implemented and executed by the information system through mechanisms contained in the hardware
software
or firmware components of the system." This definition encompasses a CCTV system.
3. (ISC)². (2022). CC Certified in Cybersecurity Official Study Guide. Chapter 2
"Incident Response
Business Continuity and Disaster Recovery
" p. 45. This source defines administrative controls as including "policies
procedures
standards
and guidelines" and "awareness and training
" which directly corresponds to options A
B
and D.