2-8 Flashcards
What are some control guidance examples?
NIST SP 800-53, NIST CSF, ISO 27014:2020
What is a control objective?
Statement of a desired results or purpose to be achieved by implementing a control or set of controls.
What is a countermeasure?
Controls implemented to address a specific threat. They are usually reactive whereas controls tend to be proactive.
What is defense in depth?
Layered security of diverse controls
What are the processes of fine tuning controls for an organization?
Scoping: Eliminating not applicable baselines, Tailoring: Customizing control to the organization, Compensating: Substituting a control with a different control, Supplementing: Augmenting the baseline recommended controls