CompTIA Security+ > Selecting Infrastructure Controls > Flashcards
What is Control?
A protective measure put in place to reduce potential risks and safeguard an organization’s assets
What is Least Privilege?
Users and systems should have only necessary access rights to reduce the attack surface
What is Defense in Depth?
Utilize multiple layers of security to ensure robust protection even if one control fails
What is a Risk-based Approach?
Prioritize controls based on potential risks and vulnerabilities specific to the infrastructure
What is Lifecycle Mangement?
Regularly review, update, and retire controls to adapt to the evolving threat landscape
What is an Open Design Principle?
Ensure transparency and accountability through rigorous testing and scrutiny of controls