Chapter 5.7 Flashcards
Technical
A technical control is implemented in operating systems, software, and security appliances. Examples include Access Control Lists (ACL) and Intrusion Detection Systems.
Deterrent
A deterrent control may not physically or logically prevent access, but rather psychologically discourages an attacker from attempting an intrusion. A warning sign is an example of a deterrent control.
Preventative
A preventive control is used to physically or logically restrict unauthorized access. A system password and physical door lock are examples of preventive controls.
detective
A detective control may not prevent or deter access, but it will identify and record any attempted or successful intrusion. A security camera system is an example of a detective control.
Administrative
Administrative security controls are used to determine behavior through policies, procedures, and guidance.
Corrective
A corrective control responds to and fixes an incident. It may also prevent reoccurrence. An example of a corrective control is antivirus software.
Compensative
A compensating control does not prevent an attack, but can restore functionality of systems through other means, such as a backup.