Controls Flashcards
4 categories of controls
Avoidance
Deterrence
Resistance
Responsive
Avoidance controls
Seek to keep threat actor from contact with the asset.
Deterrence controls
Keep contact event from becoming a threat event.
Limits probability of action, limiting threat event frequency.
Resistance controls
Decreases the vulnerability of an asset. Keep threat event from becoming a loss event
Limits LEF.
Responsive controls
Limit the amount of loss an organization experiences.
Break threat actors contact with asset.
Limits loss magnitude
Avoidance control examples
Physical security, network segmentation, reducing the number of assets
Deterrence examples
AUP, network monitoring, security cameras, data masking, guards, logon screens
Resistance examples
Access management, authentication, config management, patching, bulletproof glass
Responsive examples
Insurance, redundancy, IR, encryption, data destruction, crisis communication, agreements for discounted credit monitoring and legal defense costs, PR campaigns.
What are controls?
Technical elements deployed to keep bad things from happening or reduce loss.
Avoidance controls limit…
Threat event frequency
Deterrence controls limit…
Probability of action and threat event frequency
Resistance controls limit…
Loss event frequency
Responsive controls limit…
Loss magnitude and risk