Controls Flashcards

1
Q

4 categories of controls

A

Avoidance
Deterrence
Resistance
Responsive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Avoidance controls

A

Seek to keep threat actor from contact with the asset.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Deterrence controls

A

Keep contact event from becoming a threat event.

Limits probability of action, limiting threat event frequency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Resistance controls

A

Decreases the vulnerability of an asset. Keep threat event from becoming a loss event

Limits LEF.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Responsive controls

A

Limit the amount of loss an organization experiences.

Break threat actors contact with asset.

Limits loss magnitude

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Avoidance control examples

A

Physical security, network segmentation, reducing the number of assets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Deterrence examples

A

AUP, network monitoring, security cameras, data masking, guards, logon screens

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Resistance examples

A

Access management, authentication, config management, patching, bulletproof glass

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Responsive examples

A

Insurance, redundancy, IR, encryption, data destruction, crisis communication, agreements for discounted credit monitoring and legal defense costs, PR campaigns.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are controls?

A

Technical elements deployed to keep bad things from happening or reduce loss.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Avoidance controls limit…

A

Threat event frequency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Deterrence controls limit…

A

Probability of action and threat event frequency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Resistance controls limit…

A

Loss event frequency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Responsive controls limit…

A

Loss magnitude and risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly