Control Types Flashcards
What are Managerial Controls?
Written by managers to create policies and procedures to reduce risk
What are the types of Managerial Controls?
Annual Risk Assessment
Pentesting and Vulnerability Scanning
What are Operational Controls
Executed by company personnel during day to day
What are the types of Operation Controls?
Security Awareness Training
Change Management
Business Continuity
What are Technical Controls?
Implemented by the IT team to reduce risk
What are the types of Tech Controls?
Firewall Rules
Antivirus
Screen Savers
Screen Filters
IPS/IDS
What are Deterrent Controls?
Measures to deter intruders away
What are Detective Controls?
Measures to investigate incidents
Corrective Controls?
Actions to recover from an incident
Compensating Controls?
Secondary controls to be used in case of a failure
Preventative Controls?
In place to deter attacks such as disabling accounts
Access Controls?
Identification
Authentication
Authorization
Discretionary Access Control?
Controls only given to a user to perform their job
Owner is the person that creates data and is responsible for authorizing who has access
Mandatory Access Control (MAC)
Classification level of data
Role Based Access Control?
A subset of a department carrying out duties