COMPARING SECURITY ROLES AND SECURITY CONTROLS Flashcards
What is a security Control?
Something designed to give a system or data asset the properties of Confidentiality, Integrity, Availability, and Non-repudiation
What is a technical Control?
Control, implemented as a system (hardware,software,firmware)
What is an Operational Control?
Implemented by people rather than systems (security Guards, training)
What is a Managerial Control?
Gives oversight of information System (risk ID tool)
Security Control Categories?
Technical, Managerial, Operational
Security Control Function Types?
Preventative, Detective, Corrective, Physical, Deterrent, Compensating
Preventative Control Function?
Acts to eliminate or reduce likelihood of attack
Detective Control Function
Does not prevent or Deter, but will ID/record any attempt intrustion
Corrective Control Function
Acts to eliminate or reduce the impact of an intrusion
Physical Control Function
Deter/Detect Physical access (Alarms/locks cameras)
Deterrent Control Function
May not prevent access, but discourages it
Compensating Control Function
Substitute for principal control
What is A Cybersecurity Framework?
A list of activities and objectives undertaken to mitigate risks
What is NIST (CSF)?
National Institute of Standards and Technology : Focuses solely on IT security
What Does ISO 27k Focus on?
Personal Data and Privacy