Security Frameworks and Controls Flashcards
What are security frameworks?
Guidelines used for building plans to help mitigate risk and threats to data and privacy. They help organizations adhere to compliance laws and regulations.
What are security controls?
Safeguards designed to reduce specific security risks. They are measures organizations use to lower risk and threats to data and privacy.
What is the Cyber Threat Framework (CTF)?
A U.S. government framework that provides a common language for describing and communicating information about cyber threat activity, helping professionals analyze and share information efficiently.
What is ISO/IEC 27001?
An international framework that enables organizations to manage the security of assets like financial information, intellectual property, employee data, and information entrusted to third parties.
What are physical controls? Give examples.
Security measures you can physically touch:
- Gates, fences, and locks
- Security guards
- CCTV and surveillance cameras
- Access cards or badges
What are technical controls? Give examples.
Technology-based security measures:
- Firewalls
- Multi-factor authentication (MFA)
- Antivirus software
What are administrative controls? Give examples.
Procedural security measures:
- Separation of duties
- Authorization
- Asset classification
How do controls relate to security goals?
Controls are used alongside frameworks to:
- Prevent security issues
- Detect security issues
- Correct security issues
What is an example of how frameworks and controls work together?
In healthcare, organizations use frameworks to comply with HIPAA, while implementing specific controls like MFA to protect patient medical records.