1A. Identify Security Control Types obj 5.3 Flashcards
Role of Cybersecurity analyst
Responsible for protecting sensitive information and preventing unauthorised access to data and systems
Duties of a Cybersecurity analyst
- Implementing and configuring security controls
- working in SOC or CSIRT
- auditing security processes and procedures
- maintaining up-to-date threat intelligence
SOC
Security Operations Centre
- A location where an organisation’s information assets are monitored and protected
- Hard to finance and maintain, used by larger orgs (gov, health) that deal with PII
Key principle of a SOC
1) supported by organisational policies
2) balances size/presence without overstepping its bounds
3) motivated staff
4) perform incident response
5) collab with other SOCs
What is Security Control?
Technology and procedures put into place to mitigate vulnerabilities and risk to ensure the CIAN of data
Name the 3 types of classes of controls
1) Technical (Logical)
- Implemented as a system (hardware, software, firmware)
2) Operational
- implemented by people rather than systems
3) Managerial
- provides oversight of the information system and addresses the design and implementation of security controls
What are Preventative controls? Name an example.
A control that acts to eliminate or reduce likelihood that an attack can succeed. E.g., Security awareness training, hardening, security guards, account disablement policy
What are Detective controls? Name an example.
A control that does not deter or prevent access, but identifies and records any attempts of intrusion. E.g., SIEM. Log monitoring, motion detection
What are Corrective controls? Name an example.
A control that acts to eliminate or reduce the impact of an intrusion event. E.g., IPS, backup and recovery
What are Physical Controls? Name an example.
Type of security control that acts against in-person intrusion attempts. E.g., CCTV, Security guards, Biometrics
What are Deterrent controls? Name an example.
A security control that discourages instruction attempts. E.g., Cable locks, video surveillance, guards
What are Compensating controls? Name an example.
A security control that acts as a substitute for a principle control that cannot be implemented due to financial, infrastructure, or impractical reasons. E.g., Encryption, TOTP