1.1 Security Controls Flashcards
What are the four main types of security controls in cybersecurity?
- Technical
- Managerial
- Operational
- Physical
Technical Control
Implemented through technology-based security measures.
Managerial Control
Implemented through policies, procedures, and governance to manage security risks.
Operational Control
Implemented through human-driven processes for secure operations.
Physical Control
Implemented to protect physical access to systems and infrastructure.
What are the 6 security control functions?
- Preventive
- Deterrent
- Detective
- Corrective
- Compensating
- Directive
Preventive
Stops security incidents before they happen (e.g., firewalls, encryption, MFA).
Deterrent
Discourages threats by making attacks less appealing (e.g., security cameras, warning signs, fences, guard dogs).
Detective
Identifies and alerts about security events (e.g., IDS, security logs)
Corrective
Fixes issues after an incident occurs (e.g., backups, patching).
Compensating
Provides alternative protection when a primary control isn’t available (e.g., extra monitoring when MFA isn’t possible).
Directive
Enforces security policies and guidelines (e.g., security policies, procedures, banners).