Section 1.1 - Security Controls Flashcards

1
Q

What are security controls used for?

A

Security Controls are used to prevent security events, minimize the impact, and limit the damages of security events.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are technical controls?

A

These are controls that we implement using some type of a technical system such as:
- Operating System Controls (Policies)
- Firewalls
- Antivirus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are managerial controls?

A

Managerial controls are documentations such as Security Policies Documentation or Standard Operating Procedures (SOP).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are operational controls?

A

Operational controls use people to set security controls, such as security guards, security awareness programs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are physical controls?

A

These are controls that would limit someones physical access to a room, building or system. Type of physical controls are:
- Guard Shack, Fences, Locks, Badge Readers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the control types?

A

Control types are Preventive, Deterrent, Detective, Corrective, Compensating, Directive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is preventive control type?

A

This control type prevents someones access to a specific resource. These are usually
- (technical) firewall rules,
- (physical) door locks,
- (operational) guard shack checking identification,
- (managerial) policy documentation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is deterrent control type?

A

Deterrent control types tries to discourage someone from an intrusion attempt.
Examples of this control type are
- (technical) application splash screens asking to log in,
- (managerial) threat of demotion (if they access unintended data),
- (physical) posted warning signs
- (operational) reception desk check in

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is detective control type?

A

Detective control types identify and log an intrusion attempt. This control type may not prevent the intrusion, but it warns that an intrusion is occurring.
Examples of this control type are:
- (technical) Review of system logs,
- (managerial) review logging report,
- (operational) regular patrol of the property,
- (physical) enabling of motion detectors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a corrective control type?

A

A corrective control is something that occurs after the security event has been detected. It’s used to reverse the impact of the event, or allow to continue operating with minimal downtime.
Examples of this security control are:
- (technical) Restoring from backups to mitigate a ransomware infection
- (operational) Contacting law enforcement
- (managerial) Create policies for how to mitigate security controls
- (physical) Use fire extinguisher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is compensating control type?

A

A compensating control type uses other means temporarily to mitigate security events.
Examples of this security control are:
- (technical) Firewall blocking a specific application instead of patching the app
- (managerial) Implementing a separation of duties
- (operational) Requiring increased guard duties
- (physical) Using a generator in case of power loss

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a directive control type?

A

A directive control type means you are directing someone to do something more secure.
Example:
- (technical) Requiring everyone to store sensitive files in a protective folder
- (managerial) Creating compliance policies and procedures
- (operational) Training users on proper security policies
- (physical) Posting a sign “Authorized Personnel Only”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly