What are Technical controls also called?
Logical security controls - they’re executed by computer systems using technology
Name 3 examples of Technical controls
1) Encryption 2) Firewalls 3) IDS/IPS
What type of control is Configuration Management?
OPERATIONAL (not technical!) - it’s day-to-day maintenance tasks performed by people
What are the 3 characteristics of Managerial controls?
1) Also called Administrative controls 2) Focused on reducing risk 3) Documented in written policies
Configuration management is Operational. Risk assessment is ___?
MANAGERIAL - it’s strategic planning/governance, not day-to-day tasks
Name 3 examples of Operational controls
1) Configuration management 2) Patch management 3) System backups (day-to-day maintenance by people)
What type of control is Patch Management?
OPERATIONAL - routine maintenance activity
Which control type do Data Backups fall under?
OPERATIONAL (not physical!)
Which control type do Firewalls fall under?
TECHNICAL (not physical!) - they’re computer-executed
What type of control is Asset Management?
MANAGERIAL/OPERATIONAL (not physical!) - it’s about tracking and managing resources