1/8
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced |
---|
No study sessions yet.
Managerial Control
A category of security control that gives oversight of the information system. Risk assessments, vulnerability assessments.
Operational Control
help ensure that the day-to-day operations of an organization comply with the security policy. Awareness and training, configuration management, media protection, physical and environment protection.
Technical Control
A category of security control that is implemented as a system (hardware, software, or firmware). Technical controls may also be described as logical controls. Encryption, antivirus software, IDSs, IPSs, Firewalls, Least privilege
Preventative Control
attempt to prevent an incident before it occurs. n Hardening, training, Security guards, change management, account disablement policy
Detective Control
Attempt to discover incidents after they have occurred. Log monitoring, SIEM systems, security audit, video surveillance, Motion detection, IDSs
Corrective Control
attempt to reverse the impact of an incident; includes IPS, backups and system recovery. Backups and system recovery, incident handling processes.
Deterrent Control
attempt to discourage individuals from causing an incident. Cable locks, physical locks
Compensating Control
are alternative controls when a primary control is not feasible
Physical Control
refer to controls you can physically touch