Security Controls Flashcards
What are the 4 types of Security controls used to prevent Security events?
Technical
Managerial
Operational
Physical
What are technical controls and provide some examples?
These are controls implemented using some type of technical system.
Firewalls
Anti-Virus
IDS
IPS
Policies and Procedures within an operating system to allow or disallow certain functions
What are managerial controls (administrative controls) and provide some examples?
Managerial controls are strategic and are geared toward managing the human and process aspects of cybersecurity.
Security policies
Standard operating procedures
Risk management
Compliance monitoring
Third party management
What are physical controls and provide some examples?
These are controls that limit physical access to a building, room or a device(s).
Guard shack
Fences, locks
Badge readers
What are operational controls and provide some examples?
Operational controls are executed by people and involve hands on activities.
Security guards
Cybersecurity awareness programs
What are the different control types?
Preventive controls
Deterrent controls
Detective controls
Corrective controls
Compensating controls
Directive controls
What is the purpose of security controls?
Security controls are used to prevent security events, minimise the impact and limit the damage.
What are security controls used to protect?
Data, People, Computer Systems, Buildings & everything within an organisation.
What are preventive controls?
This is to block/limit someone’s access to a resource.
Does not allow to pass
What are deterrent controls?
This is to discourage an intrusion attempt - Does not directly prevent access
What is a detective control type?
This type of control is used to identify and log an intrusion attempt
What is a corrective control type?
This is used to apply a control after an event has been detected with the purpose of reversing the impact and to allow operations to continue with minimal downtime
What is a compensating control?
A compensating control is an alternative measure put in place to meet security requirements when a primary control cannot be implemented due to limitations such as technical constraints, costs, or organizational restrictions. Prevent the exploitation of a weakness if it cannot be corrected
What is a directive control?
Direct a subject towards security compliance - to do something more secure than less secure