Security Control Terms and Examples

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

flashcard set

Earn XP

Description and Tags

Domain 1.0: General Security Concepts

Last updated 4:52 AM on 7/23/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards

What is a Technical (Logical) Control?

Hardware or software mechanisms implemented within a system to protect data, applications, and networks. It relies on technology instead of human intervention.

2
New cards

Example: Technical (Logical) Control

Configuring multi-factor authentication (MFA) or deploying an intrusion detection system (IDS) to monitor network traffic.

3
New cards

Managerial (Administrative) Controls

Involves administrative policies, guidelines, and procedures defined by management to direct day-to-day operations, govern employee behavior, and manage organizational risk.

4
New cards

Example: Managerial (Administrative) Controls

Enforcing a corporate password rotation policy that requires users to change their credentials every 90 days.

5
New cards

Operational Controls

Implemented and executed by people instead of systems, focusing on the day-to-day execution of security processes, physical safety, and personnel management.

6
New cards

Example: Operational Controls

Conducting regular security awareness training for employees or performing periodic background checks for new hires.

7
New cards

Physical Controls

Tangible, physical barriers designed to protect hardware, facilities, data centers, and personnel from unauthorized access, environmental damage, or theft.

8
New cards

Example: Physical Controls

Installing biometric scanners, CCTV cameras, or mantraps at the entrance of a server room.

9
New cards

Preventive Controls

Measures designed to stop an incident, attack, or unauthorized access attempt from happening in the first place.

10
New cards

Example: Preventive Controls

Implementing strict firewall rules to block unauthorized inbound network traffic.

11
New cards

Deterrent Controls

Controls aimed at discouraging potential attackers or malicious actors from attempting a breach by raising the perceived risk of getting caught.

12
New cards

Example: Deterrent Controls

Controls aimed at discouraging potential attackers or malicious actors from attempting a breach by raising the perceived risk of getting caught.

13
New cards

Detective Controls

Mechanisms meant to identify and alert administrators to an active or ongoing security violation or anomaly.

14
New cards

Example: Detective Controls

Reviewing system and authentication log files to spot anomalies or indicators of compromise (IoCs).

15
New cards

Corrective Controls

Actions taken to remediate vulnerabilities, mitigate the damage of an ongoing incident, or restore a system back to a secure baseline state after a breach.

16
New cards

Example: Corrective Controls

Isolating an infected host from the network and patching exploited software vulnerabilities.

17
New cards

Compensating Controls

Alternative or backup security measures put in place when a primary control cannot be implemented due to cost, technical limitations, or operational constraints.

18
New cards

Example: Compensating Controls

Requiring manual secondary manager sign-offs for high-value financial transfers when automated system checks are temporarily unavailable.

19
New cards

Directive Controls

Rules, directives, or mandates issued by management to govern the behavior of personnel and enforce compliance with organizational security goals.

20
New cards

Example: Directive Controls

Establishing an Acceptable Use Policy (AUP) that explicitly prohibits employees from connecting unapproved personal storage drives to company workstations.