Topic 1B: InfoSec Controls Flashcards
A Security Control
Provides an asset or system with CIA
Three major control types
Technical, Operational, Management
Technical controls
Implemented as hardware, software, or firmware. AKA logic controls
Operational controls
Implemented as people performing processes or tasks, such as reviewing logs or providing training
Management controls
Oversee the controls themselves, such risk assessment or review
Control functional types
Preventive, Detective, Corrective, Physical, Deterrent, Compensating
Preventive control
Eliminates or reduces likelihood of success
Detective control
Identifies and records something happening
Corrective control
Eliminates or reduces impact
Physical control
Tangible objects, such as locks or guards
Deterrent
Warnings which discourage attempts
Compensating controls
Substitute for a specific control of equal or greater protection
ISO 27000 series
A series of security frameworks
ISO 31000 series
A series of enterprise risk management frameworks
SOC2
Evaluates Trust Services Criteria when storing or processing customer data