Control Types Flashcards

1
Q

What are Managerial Controls?

A

Written by managers to create policies and procedures to reduce risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the types of Managerial Controls?

A

Annual Risk Assessment
Pentesting and Vulnerability Scanning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are Operational Controls

A

Executed by company personnel during day to day

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the types of Operation Controls?

A

Security Awareness Training
Change Management
Business Continuity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are Technical Controls?

A

Implemented by the IT team to reduce risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the types of Tech Controls?

A

Firewall Rules
Antivirus
Screen Savers
Screen Filters
IPS/IDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are Deterrent Controls?

A

Measures to deter intruders away

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are Detective Controls?

A

Measures to investigate incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Corrective Controls?

A

Actions to recover from an incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Compensating Controls?

A

Secondary controls to be used in case of a failure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Preventative Controls?

A

In place to deter attacks such as disabling accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Access Controls?

A

Identification
Authentication
Authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Discretionary Access Control?

A

Controls only given to a user to perform their job
Owner is the person that creates data and is responsible for authorizing who has access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Mandatory Access Control (MAC)

A

Classification level of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Role Based Access Control?

A

A subset of a department carrying out duties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Rule Based Access Control?

A

Giving access to all the people in a department

17
Q

Attribute Based Controls?

A

Access is given based on the attributes of an account

18
Q

Who is responsible for labeling data?

A

Steward

19
Q

Who stores and manages classified data?

A

Custodian