Biometric authorization is the most effective control listed for restricting access to secure areas because it authenticates users based on unique physical characteristics, such as fingerprints, retina patterns, facial geometry, or hand geometry. It is stronger than a policy because it directly prevents unauthorized access. Access log reviews are detective; they identify access after it occurs rather than restricting it at the point of entry. Security cameras are also primarily detective or deterrent controls. A security policy is necessary, but it does not physically stop unauthorized entry. Internal auditors reviewing secure areas should evaluate whether physical access is limited, logged, reviewed, revoked timely, and appropriate to the sensitivity of assets protected. Therefore, Option C is correct.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit