1.1 Compare and contrast various types of security controls Flashcards
1
Q
Security Control Categories
A
- Technical Controls - Technologies, hardware, and software (IDS, FW, etc.)
- Managerial (Administrative) Controls - documented in written policies. Также risk and vulnerability assessments.
- Operational Controls - performed in day-to-day operations (Incident response plans, backup and recovery operations). Usually done by PEOPLE
- Physical Controls
2
Q
Security Control Types
A
- Preventive - build foundation
- Deterrent - discourage thread. Отпугивает
- Detective - detect and alert about already happened incidents
- Corrective - address issues after they arise. offer backups and mitigations. Restore the confidentiality, integrity, and/or availability that was affected by the incident.
- Compensating - alternative controls when a primary security control is not feasible or is not yet deployed.
- Directive - provide instruction to individuals on how they should handle security-related situations that arise.