Security Controls Flashcards

1
Q

What are the purpose of security controls?

A

-To prevent security incidents
-To minimize the impact
-To limit the damage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the four types of security controls?

A
  1. Technical
  2. Operational
  3. Managerial
  4. Physical
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are technical controls? Examples?

A

Controls implemented using systems.
Ex: Firewalls, anti-virus, operating system controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are operational controls? Examples?

A

Controls that uses ‘people’ instead of systems.
Ex: Security guards, awareness programs at work to explain best practices of IT security, lunch & learns

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are managerial controls? Examples?

A

Admin controls that are associated w/ security design & implementation.
Ex: Security policies, day-to-day processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are physical controls? Examples?

A

Controls that limit physical access.
Ex: Shack, fences, locks, badge readers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the six control types?

A
  1. Preventive
  2. Corrective
  3. Detective
  4. Directive
  5. Deterrent
  6. Compensating
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are preventive control types? Examples?

A

Controls that blocks access to resource.
Ex: Firewall, guard shack checks, on boarding policy, door locks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are deterrent controls?
Examples?

A

Controls that discourage intrusion, does not directly prevent access.
Ex: Splash screens, front reception desk, threats of demotion, posted warning signs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are detective controls? Examples?

A

Controls that identify and log an intrusion attempt, may not prevent access.
Ex: System logs, property patrols, review login reports, motion detectors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are corrective controls? Examples?

A

Controls that are applied after an event has been detected. Reverse impact.
Ex: Restore from backups, law enforcement to manage criminal activity, create policies for reporting security issues. Use fire extinguisher.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are compensating controls? examples?

A

Using other means of control, temporary & insufficient.
Ex: Firewall instead of patching, simultaneous guard duties, generator used after an outage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are directive controls? Examples?

A

Directs a subject towards security compliance.
Ex: Store all sensitive files in a protected folder, train users on security policy, create compliance policies, post a sign for ‘Authorized Personnel Only.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly