Security Control Types Flashcards
SOC
Security Operations Center: A location where security professionals monitor and protect critical information assets in an organization
Security Control
A technology or procedure put in place to mitigate vulnerabilities and risk in order to ensure the CIA triad (Confidentiality, Integrity and Availability)
Technical Control
Logical Control: A category of security control that is implemented as a system(Hardware, software or firmware)
Operational Control
Security control that is implemented by people instead of systems. Example: Security guards
managerial Control
Security Control that provides oversight of the information system
Preventative
Acts to reduce the likelihood that an attack can succeed
Detective Control
Any control that may not prevent access but will identify and record any attempted successful intrusion
Corrective Control
Any control that acts to reduce the impact of an intrusion event.
Physical Control
A type of security control that acts against in person intrusion attempts.
Deterrent Control
A type of security control that discourages intrusion attempts. Example: video camera
Compensating Control
This acts as a substitute for a principal control. Example: recommended by a security standard for a cheaper price while also having a strong security control.