Control Objectives 2 Flashcards

1
Q

Directive controls

A

Are proactive actions taken to cause or encourage a desirable event and outcome occur. Are broad in nature, used to increase the effectiveness of other controls, examples: frameworks, models, polices, guidance statements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Control category - operational

A

Operational controls are aligned with a process that are primaily implemented and executed by people (change management, testing, training)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Control classification- corrective

A

Corrective controls minimize the impact of a threat agent or modify or fix situation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Control category- technical

A

Technical control mechanism are implemented using hardware, software and/or firmware components, can be native or supplementary (firewalls, cryptography, 2FA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Control classification - preventive

A

Preventive controls stop a threat agent from being successful

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Layered security

A

Layered security (defense-in-depth) is the design and implementation of multiple overlapping layers of diverse controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Control category-Managerial

A

Managerial controls relate to risk management, governance, oversight, strategic alignment and decision making

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Control category physical

A

Physical controls are designed to address physical interactions. Generally related to buildings and equipment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Control classification : Deterrent

A

Deterrent controls discourage a threat agent from acting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Control classification : Detective controls

A

Detective controls identify and report a threat agent or a threat action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Compensating controls

A

Compensating controls are implemented in lieu of a recommended control that provided equivalent or comparable protection, can be supplemental, short-term or temporarly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Control type examples - preventive

A

Technical preventive => firewall (operating by system)
Managerial preventive => on-boarding policy (policies)
Operational preventive => guard shack (by person)
Physical preventive => door lock (made by equipment)
Blocks access to a resource, you shall not pass

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Control types examples - deterrent

A

Technical deterrent => splash screen (pop up screen for example requiring to put your credentials to gran access - software control)
Managerial deterrent => demotions (process of reducing for a lower grade)
Operational deterrent => reception desk (performing by people)
Physical deterrent => warning signs (building equipment)
This type of control does NOT encourage intrusion to go, this controls make you think twice before attack, does NOT directly prevent access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Control types examples - deterrent

A

Technical deterrent => splash screen (pop up screen for example requiring to put your credentials to gran access - software control)
Managerial deterrent => demotions (process of reducing for a lower grade)
Operational deterrent => reception desk (performing by people)
Physical deterrent => warning signs
This type of control does NOT encourage intrusion to go, this controls make you think twice before attack, does NOT directly prevent access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Control type examples - detective

A

Technical detective => system logs (performed by software)
Managerial detective => review login reports
Operational detective=> property patrols (made by people)
Physical detective => motion detectors (equipment)
Warning and log information about the attack.finding issue.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Control types examples - corrective

A

Technical corrective => backup recovery (software)
Managerial corrective => policy for reporting issues
Operational corrective => contact authorities about the crime
Physical corrective => use distinguisher (equipment)
Apply a control after event detection to reverse an impact of event or continuing operating with minimal downtime,

17
Q

Control types examples - compensating control

A

Technical compensating => block software until patch is available (software)
Managerial compensating => separation of duties
Operational compensating => require new security staff patrols (people operating)
Physical compensating => power generator ( additional equipment)
When the current controls are not sufficient, temporarily implemented before fix plan implemented

18
Q

Control types examples- directive control

A

Technical directive => file storage policies (software data type labeling)
Managerial directive => compliance policies
Operational directive=> security policy training (operated by people)
Physical directive => sign: authorized personel only ( equipment)
Directing someone to do something more secure, weak security control. Do this please type of control.