What are security controls?
What is the difference between safeguards and countermeasures?
What are the 3 different types of controls?
Describe Administrative Controls
Describe Technical Controls
Describe Physical Controls
What are security controls often based on?
What are examples of security control frameworks?
Which NIST publication covers the assessment of security and privacy controls?
NIST SP 800-53
What is required for ensuring effectiveness of the security controls?
What are the 6 security control types?
Name them in order.
Describe Deterrent security control type
Name an example
Describe Preventative security control type
Name an example
Describe Detective security control type
Name an example
Describe Compensating security control type
Name an example
Describe Corrective security control type
Name an example
Describe Recovery security control type
Name an example
Describe Directive security control type
Name an example
Which security control is likely driven by a legal requirement?
retention policy
Which security control can detect that an employee is engaging in an illegal activity over a period of time?
mandatory vacation, during which employee’s privileges are revoked
What’s the name for the degree of confidence that an organization has that its security controls are correcctly implemented?
assurance
What technique is most frequently used to assess security awarness?
surveys
What purpose are the CIS benchmarks frequently used for in organizations?
A significant benefit of a security control is when it goes unnoticed by users. What is this called?
transparency