1/33
Name | Mastery | Learn | Test | Matching | Spaced |
|---|
No study sessions yet.
Technical Controls
Controls implemented using systems
Managerial Controls
Administrative controls associated with security design and implementation
Operational Controls
Controls implemented by people instead of systems
Physical Controls
Limit physical access
Preventative
Block access to a resource
Deterrent
Discourage an intrusion attempt but does not directly prevent access
Detective
Identify and log an intrusion attempt. May not prevent access
Corrective
Apply a control after an event has been detected
Compensating
Control using other means when existing controls aren’t sufficient enough
Directive
Direct a subject towards security compliance which is a weak control
Example of a Preventative Technical Control
Firewall
Example of a Deterrent Technical Control
Splash Screen
Example of a Detective Technical Control
System Logs
Example of a Corrective Technical Control
Backup recovery
Example of a Compensating Technical Control
Block instead of patch
Example of a Directive Technical Control
File storage policies
Example of a Preventative Managerial Control
On-boarding policy
Example of a Deterrent Managerial Control
Demotion
Example of a Detective Managerial Control
Review login reports
Example of a Corrective Managerial Control
Policies for reporting issues
Example of a Compensating Managerial Control
Separation of duties
Example of a Directive Managerial Control
Compliance policies
Example of a Preventative Operational Control
Guard shack
Example of a Deterrent Operational Control
Reception desk
Example of a Detective Operational Control
Property patrols
Example of a Corrective Operational Control
Contact Authorities
Example of a Compensating Operational Control
Require multiple security staff
Example of a Directive Operational Control
Security policy training
Example of a Preventative Physical Control
Door lock
Example of a Deterrent Physical Control
Warning signs
Example of a Detective Physical Control
Motion detectors
Example of a Corrective Physical Control
Fire extinguisher
Example of a Compensating Physical Control
Power generator
Example of a Directive Physical Control
Sign: Authorized Personnel Only