Security Controls Flashcards

1
Q

What are the 4 types of Security controls used to prevent Security events?

A

Technical
Managerial
Operational
Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are technical controls and provide some examples?

A

These are controls implemented using some type of technical system.

Firewalls
Anti-Virus
IDS
IPS
Policies and Procedures within an operating system to allow or disallow certain functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are managerial controls (administrative controls) and provide some examples?

A

Managerial controls are strategic and are geared toward managing the human and process aspects of cybersecurity.

Security policies
Standard operating procedures
Risk management
Compliance monitoring
Third party management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are physical controls and provide some examples?

A

These are controls that limit physical access to a building, room or a device(s).

Guard shack
Fences, locks
Badge readers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are operational controls and provide some examples?

A

Operational controls are executed by people and involve hands on activities.

Security guards
Cybersecurity awareness programs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the different control types?

A

Preventive controls
Deterrent controls
Detective controls
Corrective controls
Compensating controls
Directive controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the purpose of security controls?

A

Security controls are used to prevent security events, minimise the impact and limit the damage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are security controls used to protect?

A

Data, People, Computer Systems, Buildings & everything within an organisation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are preventive controls?

A

This is to block/limit someone’s access to a resource.
Does not allow to pass

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are deterrent controls?

A

This is to discourage an intrusion attempt - Does not directly prevent access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a detective control type?

A

This type of control is used to identify and log an intrusion attempt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a corrective control type?

A

This is used to apply a control after an event has been detected with the purpose of reversing the impact and to allow operations to continue with minimal downtime

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a compensating control?

A

A compensating control is an alternative measure put in place to meet security requirements when a primary control cannot be implemented due to limitations such as technical constraints, costs, or organizational restrictions. Prevent the exploitation of a weakness if it cannot be corrected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a directive control?

A

Direct a subject towards security compliance - to do something more secure than less secure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly