5.1 Security Controls Flashcards

1
Q

What are Managerial controls?

A

Security policies, standard operating procedures.

These address security design and implementation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are operational controls?

A

Security guards, awareness programs.

Controls implemented by people.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are technical controls?

A

Firewalls, anti-virus, etc.

Controls using systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are preventive controls?

A

Physically control access
Door lock
Security guard
Firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are detective controls?

A

They may not prevent access, just detect it.
Identifies and records intrusion attempts.
Motion detector, IDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are corrective controls?

A

These are designed to mitigate damage.
IPS can block attacker
Backups can mitigate a ransomware infection
Backup site can provide options during weather storm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are deterrent controls?

A

May not directly prevent access.
Discourages intrusion attempt.
Warning sign, login banner, lights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are compensating controls?

A

Doesn’t prevent attack. Restores by other means.
Re-image or restore from backup.
Hot site
Backup power system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are physical controls?

A

Fence, door lock, real-world security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Note:

A

Some controls technologies fall under multiple categories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly