Section 2.14 Security control types Flashcards
Objectives 1.1 Compare and contrast various types of security controls Objectives 1.2 - Summarise fundamental security concepts
6 basic types
Types of Security Controls
PDDCCD
- Preventitive controls
- Deterrent Controls
- Detective Controls
- Corrective Controls
- Compensating Controls
- Directive Controls
Security Pros implement different security controls depending on what security threat they are addressing
1
Preventitive controls
Proactive measures taken to stop security threats/breaches
e.g Firewall is preventive measure as it can filter incoming/outcoming traffic to block any harfmul data packages before they impact the organisations network
2
Deterrent Controls
Discourage potential attackers by making the effort seem less appealing or more challenging
e.g Signs to warn bad actors (warning signs or banners)
3
Detective Controls
Monitor and alert organisations to malicious activity
e.g Intrusion detection system which is constantly scanning a network for malicious activity
4
Corrective Controls
Mitigate potential damage and restore systems to their normal state
e.g The anti-virus software can actually quarantine and remove suspicious files
5
Compensating Controls
Alternative security measures that are implemented when primary security controls are not feasible or effective
e.g Legacy systems cannot support WPA3 so instead you can use WPA2 with a VPN
6
Directive Controls:
Policies/documentation to guide, inform or mandate actions to help mitigate threat.
e.g An organisation acceptable use policy (AUP) is a directive contol as it provides guidlines