2.1 Security Measures Flashcards
Summarise various security measures and their purposes
Logical controls
Prevent or allow access to resources once a user’s identity has been established. Can be hardware or software.
Auditing of logical controls
Once-off; examining the controls and procedures in place
Monitoring of logical controls
Ongoing checks of the controls and procedures in place
Managerial controls
Focuses on the design of the security or the policy implementation associated with the security
List three controls that fall under ‘managerial’
- Data classification and labelling
- Personnel supervision
- Security awareness training
Operational controls
Controls managed by people
Give two examples of operational controls
Guards at the front doors; security awareness training
Technical controls
Using own systems to prevent security events from occurring
Give two examples of technical controls
Firewall on the network; antivirus on workstations
Provide one advantage and one disadvantage of see-through fences
Employees and guards can see incoming threats; outsides can see inside the property
Provide one advantage and one disadvantage of non see-through fences
Outsiders are prevented from seeing in, but employees and guards can’t see incoming threats
What are some considerations when installing bollards?
Will they protect the most vital assets?
Do they still integrate with the environment so as not to be off-putting to customers/staff?
List two best practices for lighting
Always on and having motion sensors
Preventive control
Prevents access to a particular area
Give three examples of preventive controls
- Locks on a door
- Security guard
- Firewall
Detective control
Identifies and records that a security event has occurred but may not be able to prevent access
Give two examples of a detective control
- Motion sensor
- IDS
Corrective control
Designed to mitigate any damage that has occurred because of a security event
Give two examples of a corrective control
- IPS
- Offsite backup
Deterrent
A security measure that may deter someone from performing and intrusion
Compensating control
Attempts to recover from an intrusion by compensating for the issues caused
Give two examples of a compensating control
- Buying a new device and restoring from backup to replace an old one
- Having a generator in case of loss of power
Physical control
Something tangible that would prevent the security event