5.1 Governance - Controls Flashcards
1
Q
Define managerial security controls (2)
A
- Defining policies and procedures that the organization is expected to follow
- Standard Operating Procedures
2
Q
Define operational security controls (2)
A
- Controls that are managed by people
- Security guards, awareness program about phishing
3
Q
Define technical security controls (2)
A
- Systems-based controls
- Anti-virus, firewalls
4
Q
Define preventative control type (2)
A
- Something that prevents access
- Locks on a door, firewall
5
Q
Define detective control type (2)
A
- Identifies or records that a security event has occurred
- Motion detectors, IDS
6
Q
Define corrective control type (2)
A
- Control that mitigates damage by a security event
- IPS, restoring data from backup
7
Q
Define deterrent control type (2)
A
- Control that doesn’t prevent, but may deter a security event
- Warning signs, login banner, lights
8
Q
Define compensating control type (2)
A
- A control that recovers from an event by compensating for losses
- Backup power or generators, purchasing a new laptop and restoring it from backup
9
Q
Define physical control type (2)
A
- Something that physically provides security
- Door locks, fence