Control Types Flashcards

1
Q

Preventive (Control Type)

A

Blocks access to a resource.

Examples of four types:

Technical ie; firewalls
Managerial ie; Security policy
Operational ie; Guard shack checks all IDs
Physical ie; Locks on doors enabled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Deterrent (Control Type)

A

Discourages an intrusion attempt.
Does not directly prevent access.

Makes attacker think twice.

Example of four types:
Technical ie; Application splash screens
Managerial ie; Threat of demotion
Operational ie; front reception desk
Physical ie; Posted warning signs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Detective (Control Type)

A

Identify, alert and log intrusion attempt.
May not prevent access.

Technical ie; Collect and review system logs
Managerial ie; Review log in reports
Operational ie; Regularly patrol property
Physical ie; Enable motion detectors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Corrective (Control Type)

A

Occurs after event.
Continue with minimum downtime or reverse impact.

Technical ie; restore from backups mitigating ransomware infection
Managerial ie; Policies for reporting security issues
Operational ie; Contact law enforcement
Physical ie; Use fire extinguisher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Compensating (Control Type)

A

Issue has occurred and other means are used to temporarily mitigate the issue.
Prevents continued exploitation of issue.

Technical ie; Firewall blocks a specific app instead of patching it
Managerial ie; Implement separation of duties
Operational ie; Require simultaneous guard duties
Physical ie; Generator used after power outages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Directive (Control Type)

A

A relatively weak security control.
Directs a subject towards a security compliance.
“Do this please….”

Technical ie; Store all sensitive fils in a protected folder
Managerial ie; Create compliance policies and procedures
Operational ie; Train users on proper security policy
Physical ie; Post a sign “For Authorized Personnel Only”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Control Types

A

Different categories of security risks:
-Technical
-Managerial
-Operational
-Physical

Can combine types.
New types can evolve.
Different organizations use different types.

Used to protect assets: Data, physical or computer systems.
Prevents security events
Minimizes impact
Limits damage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Technical Controls

A

Implemented using some type of system.
Examples:
Operating system controls
Firewalls
Anti-virus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Managerial Controls

A

Administrative controls associated with security design and implementation.

Examples:
Security policies
SOPs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Operational Controls

A

Uses people to implement.

Examples:
Security guards
Awareness programs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Physical Controls

A

Limits physical access

Examples:
Guard shack
Fences
Locks
Badge readers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly