Security Controls 5.7 Flashcards
Security Controls
Many different types of risks. Assets are varied; computer systems, physical property, data. Our job is to prevent security events, minimize their impact, and limit the damage.
Control Types
Technical Control, Administrative Control, Physical Control
Deterrent
May not prevent access, but discourages intrusion. These are warning signs, login banners. These are preventive in nature. Physical control access; door locks, security guard, firewall.
Detective
May not prevent access, but identifies and records any intrusion attempts. Motion detectors, IDS/IPS. There is some compensation to attacks; you can restore your data from known good backups.
Corrective
Designed to mitigate damage. IPS can block an attacker. Backups can mitigate a ransomware infection, a backup site can provide options if a storm hits.