Functional Order of Physical Controls
6 D’s: Deter, Deny, Detect, Delay, Determine, Decide
COBIT
Control Objectives for Information and Related Technologies. It’s a security control framework
COBIT 6 Principles
Classes of Controls (3)
Administrative: aka managerial
Logical/Technical
Physical
<assets>
</assets>
Tailoring
Aligns controls with business security requirements. Includes assigning control values.
Scoping
Part of Tailoring process where you review list of baseline security controls and select only those that apply to the IT systems in use. Scoping eliminates controls that don’t apply to business.