Control Types (Technical/Operational/Managerial/Physical) Flashcards

(10 cards)

1
Q

What are Technical controls also called?

A

Logical security controls - they’re executed by computer systems using technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Name 3 examples of Technical controls

A

1) Encryption 2) Firewalls 3) IDS/IPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What type of control is Configuration Management?

A

OPERATIONAL (not technical!) - it’s day-to-day maintenance tasks performed by people

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 3 characteristics of Managerial controls?

A

1) Also called Administrative controls 2) Focused on reducing risk 3) Documented in written policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Configuration management is Operational. Risk assessment is ___?

A

MANAGERIAL - it’s strategic planning/governance, not day-to-day tasks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Name 3 examples of Operational controls

A

1) Configuration management 2) Patch management 3) System backups (day-to-day maintenance by people)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What type of control is Patch Management?

A

OPERATIONAL - routine maintenance activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which control type do Data Backups fall under?

A

OPERATIONAL (not physical!)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which control type do Firewalls fall under?

A

TECHNICAL (not physical!) - they’re computer-executed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What type of control is Asset Management?

A

MANAGERIAL/OPERATIONAL (not physical!) - it’s about tracking and managing resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly