Security controls 1.1 Flashcards

(11 cards)

1
Q

Technical controls.

A

Controls that are operated using systems. Firewalls, Antivirus.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Managerial controls.

A

Administrative controls associated with security design & implementation. Security polices & standard operating procedures (SOP).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Operational controls

A

Use people for these. Security guards, Awareness programs,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Physical controls

A

Limiting physical access. guard shack, fences, badge readers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Preventive controls

A

Block access to a resource. Firewall rules, follow security policy, guard shack checks identifications, door locks on.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Deterrent controls.

A

Gives someone trying to access a resource second though or trouble. Splash screens, threat of demotion, posted warning signs, front reception desk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Detective control

A

Identifies and logs an intrusion attempt. May not prevent access. Reviews system logs, enable motion detectors, review login reports.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Corrective control

A

Applies after an event has occurred. Can sometimes reverse the effect of the event. Continue operating with minimal downtime. Correct the problem by restoring backups that can mitigate a ransomware infection, create policies for security issues, contact law enforcement or use a fire extinguisher.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Compensating control

A

Control using other means for security event. Can be use don temp basis to resolve. Prevent the exploitation of a weakness. Firewall blocks an application instead of patching it. implement separation of duties, require simultaneous guard duties, generator used after power outage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Directive control type

A

Relatively weak control cause your directing someone toward security compliance. Store all sensitive files in a protected folder, create compliance policy and procedures, train users on correct policy, makes “authorized users only” sign.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

how are security controls managed?

A

There are many categories of control some that some companies will combine. New control types are created. Each org will use different controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly