Security Controls - CompTIA Security+ SY0-701 - 1.1

0.0(0)
studied byStudied by 0 people
GameKnowt Play
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/35

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

36 Terms

1
New cards

Security Controls

• Security risks are out there

- Many different types to consider

• Assets are also varied

- Data, physical property, computer systems

• Prevent security events, minimize the impact, and limit the damage

- Security controls

2
New cards

Technical Controls

- Controls implemented using systems

- Operating system controls

- Firewalls, anti-virus

3
New cards

Managerial Control

- Administrative controls associated with security design and implementation

- Security policies, standard operating procedures

4
New cards

Operational Controls

- Controls implemented by people instead of technical systems.

- Security guards, awareness programs

5
New cards

Physical Controls

Limits physical access

- Guard shack

- Fences, locks

- Badge readers

6
New cards

Preventive Controls

Block access to resource

7
New cards

Technical Preventative Control example

Firewall rule, antivirus

8
New cards

Managerial Preventative Control example

Security Policy, On-boarding policy

9
New cards

Operational Preventative control example

Guard shack

10
New cards

Physical Preventative control example

Door Lock, badge reader

11
New cards

Deterrent Controls

- Discourages an intrusion attempt

- Doesn't directly prevent access

12
New cards

Technical Deterrent Control example

Application Splash screen

13
New cards

Managerial Deterrent Control example

Threat of demotion, sanctions, punishments

14
New cards

Operational Deterrent Control example

Front Desk receptionist

15
New cards

Physical Deterrent Control example

Posted warning signs

16
New cards

Detective Controls

- Identify and log an intrusion attempt

- May not prevent access

17
New cards

Technical Detective Control

Collecting and review system logs

18
New cards

Managerial Detective Control example

Review login reports

19
New cards

Operational Detective Control example

Property Patrols

20
New cards

Physical Detective Control example

Enabling motion detection, using window sensors

21
New cards

Corrective Controls

- Applying a control after an event has been detected

- Reverse the impact of an event

- Continue operating with minimal downtime

22
New cards

Technical Corrective Control example

Restoring from backups can mitigate ransomware infection

23
New cards

Managerial Corrective Control example

Creating policies for reporting security issues

24
New cards

Operational Corrective control example

Law enforcement

25
New cards

Physical Corrective Controls example

Fire extinguisher

26
New cards

Compensating Controls

- Control procedures that compensate for the deficiency in other controls

- May be temporary

27
New cards

Technical Compensating Controls examples

Block instead of patch

28
New cards

Managerial Compensating Controls examples

Separation of duties

29
New cards

Operational Compensating Controls examples

Simultaneous security staff

30
New cards

Physical Compensating Controls examples

Power generator

31
New cards

Directive Controls

- Direct a subject towards security compliance

- A relatively weak security control

32
New cards

Technical Directive Controls examples

File storage policies

33
New cards

Managerial Directive Controls examples

Compliance policies

34
New cards

Operational Directive Controls examples

Security policy training

35
New cards

Physical Directive Controls examples

Sign: Authorized personnel Only

36
New cards

Managing security controls

- Their are many categories of control which organizations will use in multiple types

- Security controls change as systems and processes evolve