Correct Answer: A
Explanation/Reference:
Explanation:
Management controls are largely procedural in nature and in general deal with the business processes used by an organization to manage the security of the information systems. The Management Control class includes five families of security controls: Risk Assessment, Security Planning, Acquisition of Information Systems and Services, Review of Security Controls and Security Accreditation.
Incorrect Answers:
B: Personnel security is not one of the five defined families of security controls in the Management Control Class.
C: Physical and environmental protection is not one of the five defined families of security controls in the Management Control Class.
D: Documentation is not one of the five defined families of security controls in the Management Control Class.
References:
Pohlman, Martin B., Oracle Identity Management: Governance, Risk, and Compliance Architecture, 3rd Edition, Auerbach Publications, Boca Raton, 2008, p. 476