Topic 1B: InfoSec Controls Flashcards

1
Q

A Security Control

A

Provides an asset or system with CIA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Three major control types

A

Technical, Operational, Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Technical controls

A

Implemented as hardware, software, or firmware. AKA logic controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Operational controls

A

Implemented as people performing processes or tasks, such as reviewing logs or providing training

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Management controls

A

Oversee the controls themselves, such risk assessment or review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Control functional types

A

Preventive, Detective, Corrective, Physical, Deterrent, Compensating

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Preventive control

A

Eliminates or reduces likelihood of success

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Detective control

A

Identifies and records something happening

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Corrective control

A

Eliminates or reduces impact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Physical control

A

Tangible objects, such as locks or guards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Deterrent

A

Warnings which discourage attempts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Compensating controls

A

Substitute for a specific control of equal or greater protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

ISO 27000 series

A

A series of security frameworks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

ISO 31000 series

A

A series of enterprise risk management frameworks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SOC2

A

Evaluates Trust Services Criteria when storing or processing customer data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SOC2 Type 1 report

A

Measures control design

17
Q

SOC2 Type 2 report

A

Measures control performance during a span of time

18
Q

Benchmarks

A

Published by non-profits like CIS or product vendors, they establish criteria for specific configuration and settings to protect an asset

19
Q

Framework

A

Provides generic industry best-practices