Security Control Types Flashcards

(8 cards)

1
Q

What is a Security Control Type?

A

The goal or the function of a particular procedure.

What is it trying to accomplish?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Preventative Controls

A

Controls which seek to stop security incidents from occurring in the first place.

-Encryption
-App Filtering
-Access Control Systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Deterrent Controls

A

Controls which seek to discourage or deter, make people think twice about what they’re doing.

-Signage (“Restricted Area”)
-CCTV \ Cameras
-Guards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Detective Controls

A

Controls which seek to record and log actions and changes within a given environment

-CCTV / Cameras
-IPS / IDS
-SIEM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Corrective Controls

A

Controls which make it simple to correct errors and mistakes

-Backup / Restore
-IRP (Incident Response Plan)
-DRP (Disaster Recovery Plan)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Compensating Controls

A

Controls which compensate for unavoidable breaches in security posture (A windows 98 system is critical to the business and must be accessible on the network despite being insecure)

Building security “around” rather than “within”

-Segmentation
-Virtualization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Recovery Controls

A

Controls which assist with returning to normalcy after an incident

-Backup/Restore
-DRP (Disaster Recovery Plan)
-BCP (Business Continuity Plan)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Directive Controls

A

Controls which are mandatory procedures, often passed down from C-Suites, Security Teams, or federal regulation (HIPPA)

-AUP (Authorized Use Policy)
-Password Policy
-Data Classification Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly