Security Controls Flashcards
A systematic evaluation of an organization’s security practices, policies, and controls to identify vulnerabilities, ensure compliance, and improve overall security posture.
Security Audit
The process of converting data into a coded format (ciphertext) to prevent unauthorized access. It ensures confidentiality and requires a decryption key to revert to readable form.
Encryption
A set of rules and procedures that dictate how an organization protects its assets, data, and systems from security threats. It defines roles, responsibilities, and acceptable use of resources.
Organizational Security Policy
Tools that monitor network or system activity for malicious actions or policy violations. They alert administrators when potential threats are detected.
IDS (Intrusion Detection System)
The practice of systematically managing and maintaining the consistency of hardware, software, and network settings. It helps prevent security misconfigurations and ensures systems are secure and up-to-date.
Configuration Management
A network security device or software that monitors and controls incoming and outgoing traffic based on predefined security rules. It acts as a barrier between a trusted and an untrusted network.
Firewall
A security control that acts as a safeguard or countermeasure implemented using technology (hardware or software) to protect systems, networks, and data from security threats.
Technical
Encryption, Intrusion Detection Systems (IDSs), & Firewalls are examples of what type of Security Control?
Technical
A type of Security Control that is:
- Sometimes called logical security controls
- Executed by Computer Systems
- Implemented with Technology?
Technical
A security control that acts as the administrative measures that focus on the planning, implementation, and management of an organization’s security strategy.
Managerial
Security policies and procedures, Risk assessments, Security training programs, & Incident response plans are examples of what type of security control?
Managerial
A type of Security Control that is:
- Also known as administrative controls
- Documented in written policies
- Focused on protecting material assets
Managerial
A security control that has procedures and practices that people perform to ensure day-to-day security. They are implemented to manage and protect an organization’s assets effectively
Operational
Incident response processes, Backup and recovery practices, Patch Management, Configuration Management, & Monitoring and logging are examples of what type of security control?
Operational
A type of Security Control that is:
- Focused on the day-to-day procedures of an organization
- Used to ensure that the equipment continues to work as specified
- Primarily implemented and executed by people (as opposed to computer systems)
Operational
A security control whose measures are designed to protect personnel, hardware, software, and data from physical threats, such as unauthorized access, theft, or natural disasters.
Physical
Locks and keys, Security cameras (CCTV), Fences and gates, Security guards, Vestibules, Bollards/Barricades, & Security Guards are examples of what type of security control?
Physical
A security control where measures are implemented to stop security incidents from occurring by proactively protecting systems, networks, and data.
Preventive
Firewalls (block unauthorized traffic), Antivirus software (prevents malware infections), Encryption, Security training (educates employees to avoid risks) are examples of what type of security control?
Preventive
A security control that is designed to discourage potential attackers or unauthorized actions by making the consequences or difficulty of an attack evident.
Deterrent