5.1 Compare and contrast various types of controls Flashcards

1
Q

What is a security control?

A

A security control is something designed to give a system or data asset the properties of confidentiality, integrity, availability, and non-repudiation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the three security controls?

A

Technical, Operational, Managerial

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a technical control?

A

The technical control is implemented as a system (hardware, software, or firmware). For example, firewalls, antivirus software, and OS access control models are technical controls. Technical controls may also be described as logical controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is an operational control?

A

The operational control is implemented primarily by people rather than systems. For example, security guards and training programs are operational controls rather than technical controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a managerial control?

A

The managerial control gives oversight of the information system. Examples could include risk identification or a tool allowing the evaluation and selection of other security controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How many control functional types are there and name them?

A

Six. Preventative, Detective, Corrective, Physical, Deterrent, Compensating

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a preventative functional control type?

A

The preventative control acts to eliminate or reduce the likelihood that an attack can succeed. A preventative control operates before an attack can take place. Access control lists (ACL) configured on firewalls and file system objects are preventative-type controls. Anti-malware software also acts as a preventative control, by blocking processes identified as malicious from executing. Directives and standard operating procedures (SOPs) can be thought of as administrative versions of preventative controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a detective functional control?

A

The detective control may not prevent or deter access, but it will identify and record any attempted or successful intrusion. A detective control operates during the progress of an attack. Logs provide one of the best examples of detective-type controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a corrective control?

A

The corrective control acts to eliminate or reduce the impact of an intrusion event. A corrective control is used after an attack. A good example is a backup system that can restore data that was damaged during an intrusion. Another example is a patch management system that acts to eliminate the vulnerability exploited during the attack.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a physical control?

A

controls such as alarms, gateways, locks, lighting, security cameras, and guards that deter and detect access to premises and hardware are often classed separately.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a deterrent control?

A

the deterrent control may not physically or logically prevent access, but psychologically discourages an attacker from attempting an intrusion. This could include signs and warnings of legal penalties against trespass or intrusion.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a compensating control?

A

the compensating control serves as a substitute for a principal control, as recommended by a security standard, and affords the same (or better) level of protection but uses a different methodology or technology.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly