____ are countermeasures or safeguards used to reduce the chances that a threat will exploit a vulnerability.
security controls
The act of reducing risk is also called _____.
risk mitigation
three main types of IT security controls
CONTROL TYPES
Fences
Physical
CONTROL TYPES
Gates
Physical
CONTROL TYPES
CCTV
Physical
CONTROL TYPES
Surveillance
Physical
CONTROL TYPES
Repair physical damage
Physical
CONTROL TYPES
re-issue access cards
Physical
CONTROL TYPES
IPS
Technical
CONTROL TYPES
Honeypots
Technical
CONTROL TYPES
Antivirus
Technical
CONTROL TYPES
Vulnerability patching
Technical
CONTROL TYPES
reboot a system
Technical
CONTROL TYPES
hiring & termination policies
administrative
CONTROL TYPES
separation of duties
administrative
CONTROL TYPES
data classification
administrative
CONTROL TYPES
review access rights
administrative
CONTROL TYPES
audit logs
administrative
CONTROL TYPES
implement a business continuity plan
administrative
CONTROL TYPES
have an incident response plan
administrative
Risk mitigation is achieved by implementing different types of security controls depending on:
_____ controls attempt to prevent an incident from occurring.
Preventive
____ controls attempt to detect incidents after they have occurred.
Detective