Chapter 1 - Compare and contrast various types of security controls Flashcards
What are the main control categories?
technical, managerial, operational, and physical
What are technical controls?
Technology-based measures such as firewalls and encryption
Where do technical controls play a crucial role?
Within an organisation’s technical systems, including computer networks software, and data management
What is the primary focus of technical controls?
Upholding system integrity, mitigating the risk of unauthorised access, and protecting sensitive data from potential threats
List two types of technical controls
Firewalls and data encryption
What do firewalls do?
Used to protect computer networks from unauthorised access. They monitor incoming and outgoijng network traffice, filter and block ptoential threats, and reduce the risk of unauthorised intrusion
What is data encryption?
It is a technical control that converts sensitive information into a coded form, making it unreadable to unauthorised individuals
What do managerial controls encompass?
Implementation of policies, procedures, and practices by management to guide and direct the activities of individuals and teams. Through effective planning, organising, and performance monitoring, managerial controls ensure that employees are aligned with the organisation’s goals
List three types of managerial controls
Performance reviews, risk assessments, and code of conduct
What is a performance review?
Performance reviews are a managerial control that involves regular assessments of employee performance
What is a risk assessment?
Risk assessments are a managerial control that involves the systematic identification, evaluation, and mitigation of potential risks within an organisation
What is a code of conduct?
A code of conduct is a set of guidelines and ethical standards established by management to govern employee behavior
What are operational controls?
Operational controls revolve around the execution of day-to-day activities and processes necessary for delivering goods and services. They involve managing operational procedures, ensuring adherence to quality standards, enhancing productivity, and optimising efficiency
List three types of operational controls
Incident response procedures, security awareness training, and user access management
What are incident response procedures?
Incident response procedures are operational controls that outline the steps to be followed in the event of a security incident or breach
What is security awareness training?
Security awareness training is an operational control that educates employees about security threats, best practices, and organisational policies