Security Controls Flashcards

monitor, alert, and recover from attacks.

1
Q

What are Technical Controls

A

Controls implemented using systems.
- Operating System controls
-Fire Walls
-AntiVirus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are Managerial Controls

A

Administrative Controls associated with security design and implementation
-Security Policies
-Standard Operating Procedures (SOP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are Operation Controls

A

Controls implemented by people instead of systems
-Security Guards
-Awareness Programs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are Physical Controls

A

Limits Physical Access
-Guard Shack
-Fences, locks
-Badge readers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are Preventative control types

A

Blocks access to a resource
-Fire wall rules
-follow security policy
-Guard Shack checks identification
-Enable door locks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are Deterrent control types

A

Discourages intrusion attempts but does not directly prevent access
-Application splash screens
-threat of demotion
-Front desk reception
-Posted warning signs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are Detective control types

A

Identify and log intrusion attempts, may not prevent access
-Collect and review system logs
-Review login reports
-Regularly patrol the property
-Enable motion detectors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are Corrective control types

A

Applying a control after an event has been detected, reverse the impact of an event, continue operating with minimal downtime
-Restoring from backups can mitigate a ransomware infection
-Create policies for reporting security issues
-Contact law enforcement to mange criminal activity
-Use a fire extinguisher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a Compensating control type

A

Control using other means, may be temporary
-Prevent the exploitation of a weakness
-implement separation of duties
-back up generator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a Directive control type

A

Do this please!?
-store sensitive files in a protected folder
-Create compliance policies and procedures
-Train users on proper security policy
-Post a sign for
Authorized Personnel Only”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly