1.2 Security Controls Flashcards
What are managerial controls?
Consist of managerial techniques and administrative procedures (e.g. security policies, hiring policies, disaster recovery plans, and business continuity plans)
What are operational controls?
Controls that the team performs everyday (e.g. reviewing network monitoring data, ensuring that security cameras are working, requiring users to sign in)
What are technical controls?
Based around software, applications, and security appliances (e.g. intrusion detection system, intrusion prevention system, access control apps, adaptive security appliances)
What are some preventative controls?
Adaptive security appliances (consist of firewall and router combination that is capable of hosting IDS and IPS), simple updated antivirus, office access control
What are some detective controls?
They inform the security team of an event that’s occurring or provide them with logs and artifacts to help investigate the event further (e.g. networking monitoring applications, log collectors, real-time monitoring alerts, IDSs)
What are some corrective controls?
They attempt to fix any damage caused by an event (e.g. IPS, endpoint detection)
What are some deterrent controls?
Access-protected doors, security cameras, security guards
What are some physical deterrents?
Locked doors, motion sensors, fences