Controls Flashcards
1
Q
Functional Order of Physical Controls
A
6 D’s: Deter, Deny, Detect, Delay, Determine, Decide
2
Q
COBIT
A
Control Objectives for Information and Related Technologies. It’s a security control framework
3
Q
COBIT 6 Principles
A
- Provide stakeholder value
- Holistic approach
- Dynamic governance system
- Governance distinct from Management
5.Tailored to Enterprise - End to End Governance System
4
Q
Classes of Controls (3)
A
Administrative: aka managerial
Logical/Technical
Physical
<assets>
</assets>
5
Q
Tailoring
A
Aligns controls with business security requirements. Includes assigning control values.
6
Q
Scoping
A
Part of Tailoring process where you review list of baseline security controls and select only those that apply to the IT systems in use. Scoping eliminates controls that don’t apply to business.