1.1 – Security Controls Flashcards

Compare and contrast various types of security controls

1
Q

Controls implemented using some type of technical system

A

Technical

antivirus, firewalls, encryption, IDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Administrative controls associated with security design and implementation

A

Managerial

security policies, standard operating procedures, risk assessments, training programs, incident response plans

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Controls implemented by people instead of systems

A

Operational

security guards, awareness programs, backup procedures, account reviews, password reset policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Controls that limit physical access to buildings, rooms and devices

A

Physical

cameras, badge readers, fences, security guards, locks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Proactive measures implemented to thwart potential security threats or breaches

fortify

A

Preventative

aim to fortify systems before an incident occurs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Discourage attackers by making the effort seem less appealing or more challenging

deter

A

Deterrent

aim to deter attackers from attacking your systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Monitor and alert to malicious activities as they occur or shortly thereafter

watch

A

Detective

aim to detect and notify

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Mitigate any potential damage and restore systems to their normal state

correct

A

Corrective

aim to apply a control after an event has been detected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Alternative measures that are implemented when primary security controls are not feasible or effective

alternate

A

Compensating

aim to ensure protection is in tack even if ideal controls are not

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Direct someone to do something more secure rather than less secure

direct

A

Directive

aim to guide, inform or mandate actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Control Type Example:
Preventative

A
  • Technical: Firewall rules
  • Managerial: On-boarding policy
  • Operational: Guard Shack
  • Physical: Door Lock
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Control Type Example:
Deterrent

A
  • Technical: Application splash screen
  • Managerial: Threat of dismissal
  • Operational: Front Reception Desk
  • Physical: Posted warning signs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Control Type Example:
Detective

A
  • Technical: Collect/Review system logs
  • Managerial: Review login reports
  • Operational: Patrol the property
  • Physical: Motion Detectors
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Control Type Example:
Corrective

A
  • Technical: Backup recovery
  • Managerial: Reporting issue policy
  • Operational: Contact authorities
  • Physical: Fire extinguisher
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Control Type Example:
Compensating

A
  • Technical: Block instead of patch
  • Managerial: Separation of duties
  • Operational: Multiple security staff
  • Physical: Power generator
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Control Type Example:
Directive

A
  • Technical: File storage policies
  • Managerial: Compliance policies
  • Operational: Security policy training
  • Physical: Sign: Authorised personnel Only