Methodologies and Security Controls Flashcards
What is the purpose of a Security Assessment?
To check the organizations security and make sure its configured properly to thwart attacks and threats.
Note: Vulnerability Assessments Penetration Testing Internal and External Audits Self Assessments Password Analysis And More
Are these assessments required?
They may be in order to fulfill a contract, regulations, or legal requirements.
What are the two main methodologies to conduct an assessment?
Active and Passive
What is an active assessment?
These are more intrusive techniques. Scanning, hands-on testing, probing the network to find vulnerabilities. These types of assessments have the potential to bring down the network.
What is a passive assessment?
These use passive collection and analysis of network data. Looking for open source information, and anything that may find information without direct contact with the targeted systems.
Note: Passive techniques are limited in scope.
What are the first three types of security controls?
Physical, Technical, and Administrative
What is a physical control?
Security measure that physically prevent access to sensitive information or the systems that contain it.
Note: This literally means fences, door locks, etc.
What is a technical control?
These are safeguards and countermeasures to avoid, detect, counteract, minimize security risks to our systems and information.
Note: These are things like passwords and encryption etc.
What is an administrative control?
These are things to change the behavior of people such as setting a company policy or procedure.
What 3 other categories does National Institute of Standards and Technology (NIST) use?
Management, Operational, and Technical
What are management controls?
Security controls that focus on decision-making and management of risk.
What are operational controls?
Focused on things done by people.
User training, testing, disaster recovery, configuration management
What are technical controls?
Logical controls put into a system to help secure it.
Encryption, AAA, Passwords, etc
What is ANOTHER set of 3 security controls?
Preventative, Detective, and Corrective
What are preventative controls?
Preventive control: It prevents any security breach from occurring. Aimed at preventing an incident from occurring.
Example
Security guards at door,
Proximity cards or bio-metrics at the entrance to the building,
Change management policy, etc.