1.1 Controls

0.0(0)
studied byStudied by 0 people
GameKnowt Play
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/35

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

36 Terms

1
New cards

Security controls (general)

prevent “security events” minimize the impact, and limit the damage

2
New cards

Technical controls

Control category, controls implemented using systems. Software, firewalls, antivirus, operating system controls

3
New cards

Managerial controls

Control category, administrative controls associated with design and implementation, think policies or SOPs

4
New cards

Operational controls

Control category, using people as controls, security guards, awareness training programs

5
New cards

Physical controls

Control category, using physical systems to prevent breaches, fences, guard rails, guard shacks, card readers

6
New cards

Preventive control type

Blocks access to a resource, “you shall not pass“

7
New cards

Preventive control implementation (technical)

Firewall rules

8
New cards

Preventive control implementation (managerial)

following security policies

9
New cards

Preventive control implementation (operational)

enabling door locks

10
New cards

Preventive control implementation (physical)

guard shack checks all IDs

11
New cards

Deterrent control type

Discourages an intrusion, does not prevent

12
New cards

Deterrent control implementation (technical)

Security badges on splash screen

13
New cards

Deterrent control implementation (managerial)

threat of demotion

14
New cards

Deterrent control implementation (operational)

front reception desk

15
New cards

Deterrent control implementation (physical)

posted warning signs

16
New cards

Detective control type

Identifies and logs intrusion attempts, may not prevent access

17
New cards

Detective control implementation (technical)

System logs

18
New cards

Detective control implementation (managerial)

Review login reports

19
New cards

Detective control implementation (operational)

property patrols

20
New cards

Detective control implementation (physical)

motion detectors

21
New cards

Corrective control types

Applies control after a security event has occurred, reverse impact of an event

22
New cards

Corrective control implementation (technical)

Restoring corrupted system via backup

23
New cards

Corrective control implementation (managerial)

Policy for reporting security issues

24
New cards

Corrective control implementation (operational)

Contacting authorities

25
New cards

Corrective control implementation (physical)

fire extinguisher

26
New cards

Compensating control types

Control using other means, additional support for an existing control, may be temporary

27
New cards

Compensating control implementation (technical)

Firewall blocking a specific app

28
New cards

Compensating control implementation (managerial)

implement a separation of duties

29
New cards

Compensating control implementation (operational)

require multiple security staff

30
New cards

Compensating control implementation (physical)

power generator

31
New cards

Directive control types

Direct a subject towards security compliance

32
New cards

Directive control implementation (technical)

File storage policy

33
New cards

Directive control implementation (managerial)

compliance policies

34
New cards

Directive control implementation (operational)

security policy training

35
New cards

Directive control implementation (physical)

signs “authorized personnel only”

36
New cards

Yes

Can some security controls exist in multiple types or categories?