1.1 : Security Controls Flashcards

Compare and contrast various types of security controls

1
Q

Categories of Security Controls

According mechanism of action; how they are applied/enacted

A

Technical, Managerial, Operational, Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Types of Security Controls

A

Preventive, Deterrent, Detective, Corrective, Compensating, Directive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Technical Controls

A

Utilize technology to protect assets. Examples: firewalls, antivirus software, encryption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Managerial Controls

A

Focused on the mechanics of the entire top-down risk-management process. Examples: security policies, risk assessments, compliance audits. Overall risk management, incorporating change management, project management, and service acquisition.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Operational Controls

A

Regular procedures and actions by personnel. Managerial controls put into regular practice. People doing stuff. Examples: security training, regular backups, daily log checking.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Physical Controls

A

Safeguard the physical infrastructure. Examples: locks, security cameras, fences.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Preventive Controls

A

Aim to prevent security incidents from occurring in the first place. Examples: firewall configurations, secure passwords, multi-factor authentication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Deterrent Controls

A

Discourage potential attackers through visible measures. Examples: warning signs, security cameras, alarm systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Detective Controls

A

Identify and log security incidents. Examples: intrusion detection systems, log monitoring, security audits.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Corrective Controls

A

Address issues after a security incident. Examples: patching vulnerabilities, restoring data from backups, reconfiguring firewalls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Compensating Controls

A

Alternative modes of protection when standard measures aren’t feasible. Examples: using a proxy server instead of direct internet access, implementing additional monitoring, using isolation techniques.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Directive Controls

A

Mandate or enforce security policies that members of the organization must follow. Examples: mandatory security training, standard operating procedures, formal security guidelines.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly