1.1 Compare and contrast various types of security controls Flashcards

1
Q

What are the Exam Objectives (Domains)?

A

1.0 General Security Concepts 12%
2.0 Threats, Vulnerabilities, and Mitigations 22%
3.0 Security Architecture 18%
4.0 Security Operations 28%
5.0 Security Program Management and Oversight 20%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the Categories of General Security Controls

A
  • Technical
  • Managerial
  • Operational
  • Physical
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the Control Types in General Security Controls?

A

Control types
- Preventive
- Deterrent
- Detective
- Corrective
- Compensating
- Directive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are Security controls?

A

Security risks are out there
– Many different categories and types to consider
* Assets are also varied
– Data, physical property, computer systems
* Prevent security events, minimize the impact,
and limit the damage
– Security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Control categories:
Technical controls

A

– Controls implemented using systems
– Operating system controls
– Firewalls, anti-virus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Control categories:
Managerial controls

A

Administrative controls associated with security design
and implementation
– Security policies, standard operating procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Control categories:
Operational controls

A

Controls implemented by people instead of systems
– Security guards, awareness programs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Control categories:
Physical controls

A

Limit physical access
– Guard shack
– Fences, locks
– Badge readers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Control Types
Preventive

A
  • Block access to a resource
    – You shall not pass
    Prevent access
    – Firewall rules
    – Follow security policy
    – Guard shack checks all identification
    – Enable door locks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Control Types
Deterrent

A

Deterrent
– Discourage an intrusion attempt
– Does not directly prevent access
* Make an attacker think twice
– Application splash screens
– Threat of demotion
– Front reception desk
– Posted warning signs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Control Types
Detective

A

Detective
– Identify and log an intrusion attempt
– May not prevent access
* Find the issue
– Collect and review system logs
– Review login reports
– Regularly patrol the property
– Enable motion detectors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Control Types
Corrective

A

Corrective
– Apply a control after an event has been detected
– Reverse the impact of an event
– Continue operating with minimal downtime
* Correct the problem
– Restoring from backups can mitigate a ransomware
infection
– Create policies for reporting security issues
– Contact law enforcement to manage criminal activity
– Use a fire extinguisher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Control Type
Compensating

A
  • Compensating
    – Control using other means
    – Existing controls aren’t sufficient
    – May be temporary
  • Prevent the exploitation of a weakness
    – Firewall blocks a specific application instead of
    patching the app
    – Implement a separation of duties
    – Require simultaneous guard duties
    – Generator used after power outage
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Control Types
Directive

A

Directive
– Direct a subject towards security compliance
– A relatively weak security control
* Do this, please
– Store all sensitive files in a protected folder
– Create compliance policies and procedures
– Train users on proper security policy
– Post a sign for “Authorized Personnel Only”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Managing security controls

A

These are not inclusive lists
– There are many categories of control
– Some organizations will combine types
* There are multiple security controls for each category and type
– Some security controls may exist in multiple types or categories
– New security controls are created as systems and processes evolve
– Your organization may use very different controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly