1/19
Domain 1.0: General Security Concepts
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is a Technical (Logical) Control?
Hardware or software mechanisms implemented within a system to protect data, applications, and networks. It relies on technology instead of human intervention.
Example: Technical (Logical) Control
Configuring multi-factor authentication (MFA) or deploying an intrusion detection system (IDS) to monitor network traffic.
Managerial (Administrative) Controls
Involves administrative policies, guidelines, and procedures defined by management to direct day-to-day operations, govern employee behavior, and manage organizational risk.
Example: Managerial (Administrative) Controls
Enforcing a corporate password rotation policy that requires users to change their credentials every 90 days.
Operational Controls
Implemented and executed by people instead of systems, focusing on the day-to-day execution of security processes, physical safety, and personnel management.
Example: Operational Controls
Conducting regular security awareness training for employees or performing periodic background checks for new hires.
Physical Controls
Tangible, physical barriers designed to protect hardware, facilities, data centers, and personnel from unauthorized access, environmental damage, or theft.
Example: Physical Controls
Installing biometric scanners, CCTV cameras, or mantraps at the entrance of a server room.
Preventive Controls
Measures designed to stop an incident, attack, or unauthorized access attempt from happening in the first place.
Example: Preventive Controls
Implementing strict firewall rules to block unauthorized inbound network traffic.
Deterrent Controls
Controls aimed at discouraging potential attackers or malicious actors from attempting a breach by raising the perceived risk of getting caught.
Example: Deterrent Controls
Controls aimed at discouraging potential attackers or malicious actors from attempting a breach by raising the perceived risk of getting caught.
Detective Controls
Mechanisms meant to identify and alert administrators to an active or ongoing security violation or anomaly.
Example: Detective Controls
Reviewing system and authentication log files to spot anomalies or indicators of compromise (IoCs).
Corrective Controls
Actions taken to remediate vulnerabilities, mitigate the damage of an ongoing incident, or restore a system back to a secure baseline state after a breach.
Example: Corrective Controls
Isolating an infected host from the network and patching exploited software vulnerabilities.
Compensating Controls
Alternative or backup security measures put in place when a primary control cannot be implemented due to cost, technical limitations, or operational constraints.
Example: Compensating Controls
Requiring manual secondary manager sign-offs for high-value financial transfers when automated system checks are temporarily unavailable.
Directive Controls
Rules, directives, or mandates issued by management to govern the behavior of personnel and enforce compliance with organizational security goals.
Example: Directive Controls
Establishing an Acceptable Use Policy (AUP) that explicitly prohibits employees from connecting unapproved personal storage drives to company workstations.