Controls Flashcards

1
Q

Controls

A

The policies, procedures, mechanisms, systems, and other measures designed to reduce risk are known as controls .

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Three types of controls

A

1-Physical
2-Technical
3- Administrative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Preventive control

A

Used to prevent the occurrence of an unwanted event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Detective Control

A

Used to record both wanted and unwanted events. This control doesn’t enforce activity, but make event known.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Deterrent Control

A

Exists to convince someone that they should not perform some unwanted activity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Corrective Controls

A

Activated (manual or auto) after some unwanted event has occurred

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Compensating controls

A

Enacted because other direct control cannot be used.. It address the risk related to the original control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Recovery Control

A

Used to restore the state of a system or asset to its re-incident state..
Example : Usage of tool to remove virus from a computer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Why Auditors prefer preventive controls over Detective controls

A

because preventives actually block unwanted events.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why Auditors prefer Detective controls over deterrence controls

A

because detective controls record events while deterrent controls do not.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Key difference between preventive and deterrent controls

A

A deterrent control requires knowledge of the control by the potential violator—it only works if they know it exists. A preventive control works regardless of whether or not the violator is aware of it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Categories of Controls

A

Automatic and manual. IT auditors and security professional prefer automatic controls to manual.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

When should control objective established

A

Prior to the control themselves.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

COBIT 5 control framework

A

To ensure that IT is aligned with business objectives, the COBIT 5 controls framework of five principles and 37 processes is an industry-wide standard.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The five principals

A
1- Meeting Stakeholder Needs
2- Covering The Enterprise End-to-End
3- Applying a single, Integrated Framework
4- Enabling a holistic approach
5-Separating governance from Management.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

General computing Controls (GCC)

A

A set of control that apply across all of its applications and services

17
Q

What IS controls describe

A

The implementation details for GCCs.

Each GCC is mapped to a specific IS control on each system type.