1.1 – Security Controls Flashcards
Compare and contrast various types of security controls
Controls implemented using some type of technical system
Technical
antivirus, firewalls, encryption, IDS
Administrative controls associated with security design and implementation
Managerial
security policies, standard operating procedures, risk assessments, training programs, incident response plans
Controls implemented by people instead of systems
Operational
security guards, awareness programs, backup procedures, account reviews, password reset policy
Controls that limit physical access to buildings, rooms and devices
Physical
cameras, badge readers, fences, security guards, locks
Proactive measures implemented to thwart potential security threats or breaches
fortify
Preventative
aim to fortify systems before an incident occurs
Discourage attackers by making the effort seem less appealing or more challenging
deter
Deterrent
aim to deter attackers from attacking your systems
Monitor and alert to malicious activities as they occur or shortly thereafter
watch
Detective
aim to detect and notify
Mitigate any potential damage and restore systems to their normal state
correct
Corrective
aim to apply a control after an event has been detected
Alternative measures that are implemented when primary security controls are not feasible or effective
alternate
Compensating
aim to ensure protection is in tack even if ideal controls are not
Direct someone to do something more secure rather than less secure
direct
Directive
aim to guide, inform or mandate actions
Control Type Example:
Preventative
- Technical: Firewall rules
- Managerial: On-boarding policy
- Operational: Guard Shack
- Physical: Door Lock
Control Type Example:
Deterrent
- Technical: Application splash screen
- Managerial: Threat of dismissal
- Operational: Front Reception Desk
- Physical: Posted warning signs
Control Type Example:
Detective
- Technical: Collect/Review system logs
- Managerial: Review login reports
- Operational: Patrol the property
- Physical: Motion Detectors
Control Type Example:
Corrective
- Technical: Backup recovery
- Managerial: Reporting issue policy
- Operational: Contact authorities
- Physical: Fire extinguisher
Control Type Example:
Compensating
- Technical: Block instead of patch
- Managerial: Separation of duties
- Operational: Multiple security staff
- Physical: Power generator