Security Roles And Controls Flashcards
Security Control Categories
Managerial
- overseeing design and implementation
Operational
- implemented by ppl
Technical
- implemented using systems (hardware or software)
Security Control Types
Preventive (door lock, firewall)
Detective (ids, motion detector)
Corrective (IPS, backups)
Deterrent (warning signs,login banner)
Compensating (backup pwr, hot site)
Physical (fences, locks, mantraps)
CIA
Confidentiality
Integrity
Availability
NIST
National Institute of Standards and Technology
(Exclusively on IT security, rather than IT service provisioning)
Framework with 5 functions
Identify, Protect, detect, respond, recover
SOC
Security Operations Center
Location where professionals monitor and protect critical information
CIRT
Computer Incident Response Team
Computer Security Act
Requires federal agencies to develop security policies for computer systems that process confidential info
Federal Information Security Management Act
Governs security of data processed by federal government agencies
Gramm-Leach-Bliley Act
Requires financial institutions to explain how they share and protect customers private info
Sarbanes-Oxley Act
Mandates the implementation of risk assessment, internal controls and audit procedures.