Policies
High Level statements about the behavior and management intent.
Standards
Statements about boundaries
Procedures
Operating procedures
Guidelines
Helpful for use with procedures and new technologies
Types of Controls
IT Controls
Non IT Controls
Countermeasures
Layered- Defenses - Defense in depth
Types of Layered- Defenses - Defense in depth
Prevention Containment Detection and notification Reaction Evidence collection and tracking Recovery and restoration