Ch9: Implementing Controls to Protect Assets Flashcards
Layered security/defense-in-depth practices
uses control diversity, implementing administrative, technical, and physical security controls
Vendor diversity
utilizes controls from different vendors
User training
informs users of threats, helping them avoid common attacks
In the event of a fire, door access systems should…
allow personnel to exit the building without any form of authentication
Access points to data centers and server rooms should be limited to…
a single entrance and exit whenever possible
Proximity cards
credit-card sized access cards. Users pass the card near a proximity card reader and it reads data on the card. Some access control points use proximity cards with PINs for authentication
Door access systems include
cipher locks, proximity cards, and biometrics
Cipher locks do not…
identify users
Proximity cards can…
identify and authenticate users when combined with a PIN
Biometrics can..
identify and authenticate users
Tailgating
a social engineering tactic that occurs when one user follows closely behind another user without using credentials
Mantraps
allow only a single person to pass at a time
Sophisticated mantraps can
identify and authenticate individuals before allowing access
Video surveillance provides
reliable proof of a person’s location and activity. It can identify who enters and exits secure areas and record theft of assets
These provide physical security
fencing, lighting, and alarms. Often used together to provide layered security
To increase the effectiveness of fencing, lighting, and alarms, use…
motion detection methods
Infrared detectors…
detect movement by objects of different temperatures
Barricades
provide stronger barriers than fences and attempt to deter attackers
Bollards
effective barricades that can block vehicles
Effective threat deterrents for small equipment such as laptops and workstations
cable locks
Locked cabinets prevent…
unauthorized access to equipment mounted in server bays
Higher-tonnage HVAC systems
provide more cooling capacity. This keeps server rooms at lower temperatures and results in fewer failures