FUNDAMENTALS OF CYBERSECURITY Flashcards
SECURITY CONTROLS
WHAT ARE THE DIFFERENT TYPES OF SECURITY CONTROLS?
1 TECHNICAL CONTROLS (TECHNOLOGIES AND SOFTWARE USED TO MITIGATE RISKS)-> FIREWALLS , ENCRYPTION SYSTEMS , IDS , IPS
2 OPERATIONAL CONTROLS (PROCEDURES AND MEASURES THAT ARE DESIGN TO PROTECT DATA ON A DAY TO DAY BASIS)-> BACKUPS PROCEDURES, ACCOUNT REVIEWS , USERS TRAINING PROGRAMS
3 PHYSICAL CONTROLS (TANGIBLES MEASURES TAKEN TO PROTECT ASSETS)
4 MANAGERIAL CONTROLS AKA ADMINISTRATIVE CONTROLS (STRATEGIC PLANNING AND GOVERANCE OF SECURITY)
DEFINE ALL THE DIFFERENT TYPES OF SECURITY CONTROL
1 PREVENTIVE CONTROL -> PROACTIVE MEASURES IMPLEMENTED TO THWART POTENTIAL SECURITY THREATS. EXAMPLE : FIREWALL
2 DETERRENT CONTROLS -> AIM TO DISCOURAGE POTENTIAL ATTACKERS
3 DETECTIVE CONTROLS -> MONITOR AND ALERT ORGANIZATIONS TO MALICIOUS ACTIVITIES. EXAMPLE : IDS
4 CORRECTIVE CONTROLS -> MITIGATE ANY POTENTIAL DAMAGE AND RESTORE THE SYSTEMS TO THEIR NORMAL STATE.
5 COMPENSATING CONTROLS ->ALTERNATIVES MEASURES PUT IN PLACE WHEN PRIMARY SECURITY CONTROLS ARE NOT FEASIBLE
6 DIRECTIVE CONTROLS-> THEY ARE ROOTED IN POLICY OR DOCUMENTATION AND SET THE STANDARDS FOR BEHAVIOR WITHIN AN ORGANIZATION