Security Controls Flashcards
Security Controls
Solutions that mitigate threats
Security Controls
Security Controls
example of security controls
Malware scanner mitigates malware infections
Security Controls
implemented differently based on platform/vendor/user
N/W infrastructure devices
- switches
- routers
- firewalls
Security Control Categories
What should be done?
- employee background checks
Managerial/administrative
Security Control Categories
how often we must do it
periodic review of security policies and include policy reviews
Operational
Security Control Categories
How exactly will we do it.
Firewall rule config
Technical
Security Control Categories
Technical Control category
specific to IT
Security Control Types
Access control vestibule (mantraps)
Physical
Security Control Types
Log Analysis
Detective
Security Control Types
patching known vulnerabilities
Corrective
Security Control Types
Device logon warning banners
Deterrent
Security Control Types
Network isolation for Internet of Things (IoT) devices
https://www.shodan.io/
Compensating
Security Control Types
Cloud Security Alliance (CSA)
cloud Controls Matrix (CCM)
Cloud Security Control Documents
Security Control Types
Security controls must be in place to be compliant - example
Payment Card Industry Data Security Standard (PCIDSS)
Security Control Types
Risk Example
Theft of online banking creds
Risk