1.0 General Security Concepts Flashcards
What are Security Controls?
They protect assets such as data, physical property, and computer systems. They prevent security events, minimize the impact, and limit the damage
What are Technical Controls?
- Controls implemented using systems
- Operating system controls
- Firewalls, anti-virus
What are Managerial Controls?
– Administrative controls associated with security design and implementation
– Security policies, standard operating procedures
What are Operational Controls?
– Controls implemented by people instead of systems
– Security guards, awareness programs
What are Physical Controls?
– Limit physical access
– Guard shack
– Fences, locks
– Badge readers
What are preventative controls types?
- Preventive
– Block access to a resource
– You shall not pass - Prevent access
– Firewall rules
– Follow security policy
– Guard shack checks all identification
– Enable door locks
What are deterrent control types?
*Deterrent
– Discourage an intrusion attempt
– Does not directly prevent access
* Make an attacker think twice
– Application splash screens
– Threat of demotion
– Front reception desk
– Posted warning signs
What are detective control types?
- Detective
– Identify and log an intrusion attempt
– May not prevent access - Find the issue
– Collect and review system logs
– Review login reports
– Regularly patrol the proper
What are Corrective control types?
- Corrective
– Apply a control after an event has been detected
– Reverse the impact of an event
– Continue operating with minimal downtime - Correct the problem
– Restoring from backups can mitigate a ransomware
infection
– Create policies for reporting security issues
– Contact law enforcement to manage criminal activity
– Use a fire extinguisher
What are compensating control types?
- Compensating
– Control using other means
– Existing controls aren’t sufficient
– May be temporary - Prevent the exploitation of a weakness
– Firewall blocks a specific application instead of
patching the app
– Implement a separation of duties
– Require simultaneous guard duties
– Generator used after power outage
What are directive control types?
- Directive
– Direct a subject towards security compliance
– A relatively weak security control - Do this, please
– Store all sensitive files in a protected folder
– Create compliance policies and procedures
– Train users on proper security policy
– Post a sign for “Authorized Personnel Only”