Section 1 General Security Concepts Flashcards
What are security risks?
come in many different categories and types.
What are the varied assets in security?
Assets include data, physical property, and computer systems.
What is the purpose of security controls?
To prevent security events, minimize the impact, and limit the damage.
What are technical controls?
Controls implemented using systems, such as operating system controls, firewalls, and anti-virus.
What are managerial controls?
Administrative controls associated with security design and implementation, including security policies and standard operating procedures.
What are operational controls?
Controls implemented by people instead of systems, such as security guards and awareness programs.
What are physical controls?
Controls that limit physical access, including guard shacks, fences, locks, and badge readers.
What is a preventive control?
A control that blocks access to a resource.
What are examples of preventive controls?
Firewall rules, following security policy, guard shack checks all identification, and enabling door locks.
What is a deterrent control?
A control that discourages an intrusion attempt but does not directly prevent access.
What are examples of deterrent controls?
Application splash screens, threat of demotion, front reception desk, and posted warning signs.
What is the purpose of preventive controls?
To block access to resources and prevent unauthorized access.
What is the purpose of deterrent controls?
To make an attacker think twice before attempting an intrusion.
What are detective control types?
Detective control types identify and log an intrusion attempt but may not prevent access.
What actions are involved in detecting the issue?
Collect and review system logs, review login reports, regularly patrol the property, and enable motion detectors.
What are corrective control types?
Corrective control types apply a control after an event has been detected, reverse the impact of an event, and continue operating with minimal downtime.
What actions are involved in correcting the problem?
Restoring from backups can mitigate a ransomware infection, create policies for reporting security issues, contact law enforcement to manage criminal activity, and use a fire extinguisher.
What are compensating control types?
Compensating control types use other means when existing controls aren’t sufficient and may be temporary.
What actions can compensate the exploitation of a weakness?
A firewall blocks a specific application instead of patching the app, implement a separation of duties, require simultaneous guard duties, and use a generator after a power outage.
What is a directive control type?
A directive control type directs a subject towards security compliance.
It is considered a relatively weak security control.
What are some examples of directive controls?
Examples include:
- Store all sensitive files in a protected folder
- Create compliance policies and procedures
- Train users on proper security policy
- Post a sign for ‘Authorized Personnel Only’
What are security controls?
measures implemented to manage and mitigate risks.
They can be categorized into various types.
Are the lists of security controls inclusive?
No, the lists of security controls are not inclusive; there are many categories of control.
What are the main categories of security controls?
The main categories of security controls are Technical, Managerial, Operational, and Physical.