IT Auditing - Information Security Control Flashcards
1
Q
Preventative control
A
Exists to prevent the threat from coming in contact with the weakness.
They are firewalls
2
Q
Compensating controls
A
Alternate controls as designed to accomplish the intent of the original controls as closely as possible. When original designed controls cannot be used due to limitations.
3
Q
Detective Controls
A
IDS is purely detective
Acts as a motion sensor
4
Q
NIST Framework
A
Used in execution of information security/Cybersecurity compliance audit
5
Q
ISO
A
Is a European Framework; replaces of COSO/COBIT