Chapter 1: Security Concepts and Controls

0.0(0)
Studied by 1 person
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

flashcard set

Earn XP

Description and Tags

A collection of key terms and definitions covering basic security concepts, incident response teams, control categories, control types, and organizational security roles.

Last updated 2:51 PM on 8/24/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards

Security operations center (SOC)

The location where security professionals monitor and protect critical information assets in an organization.

2
New cards

Development and operations (DevOps)

A combination of software development and systems operations and refers to the practice of integrating one discipline with the other.

3
New cards

DevSecOps

A combination of software development, security operations, and systems operations and refers to the practice of integrating each discipline with the others.

4
New cards

Computer incident response team (CIRT)/computer security incident response team (CSIRT)/computer emergency response team (CERT)

Team with responsibility for incident response. The CSIRT must have expertise across a number of business domains (IT, HR, legal, and marketing, for instance).

5
New cards

Security control

A technology or procedure put in place to mitigate vulnerabilities and risk and to ensure the confidentiality, integrity, and availability (CIA) of information.

6
New cards

Managerial

A category of security control that provides oversight of information systems.

7
New cards

Operational

A category of security control that is implemented by people.

8
New cards

Technical

A category of security control that is implemented as a system.

9
New cards

Physical

A category of security control that is implemented by hardware used to deter or detect, such as alarms, gateways, locks, lighting, and security cameras.

10
New cards

Preventive

A type of security control that acts before an incident to eliminate or reduce the likelihood that an attack can succeed.

11
New cards

Access control lists (ACLs)

The collection of access control entries (ACEs) that determines which subjects (user accounts, host IP addresses, and so on) are allowed or denied access to the object and the privileges given (read-only, read/write, and so on).

12
New cards

Detective

A type of security control that acts during an incident to identify or record that it is happening.

13
New cards

Corrective

A type of security control that acts after an incident to eliminate or minimize its impact.

14
New cards

Directive

A type of control that enforces a rule of behavior through a policy or contract.

15
New cards

Deterrent

A type of security control that discourages intrusion attempts.

16
New cards

Compensating

A security measure that takes on risk mitigation when a primary control fails or cannot completely meet expectations.

17
New cards

Chief Information Officer (CIO)

A company officer with the primary responsibility of managing information technology assets and procedures.

18
New cards

Chief Technology Officer (CTO)

A company officer with the primary role of making effective use of new and emerging computing platforms and innovations.

19
New cards

Chief Security Officer (CSO)

Typically, the job title of the person with overall responsibility for information assurance and systems security.

20
New cards

Information Systems Security Officer (ISSO)

Organizational role with technical responsibilities for implementation of security policies, frameworks, and controls.