Section 6: Risk Strategies Flashcards

1
Q

7 Different Categories of Access Control

A

▪ Compensative
● Used in place of a primary access control measure in order to
mitigate a given risk
▪ Corrective
● Used to reduce the effect of an undesirable event or attack
▪ Detective
● Used to detect an attack while it is occurring and to notify the
proper personnel
▪ Deterrent
● Used to discourage any violation of the security policies, both to
attackers and insiders
▪ Directive
● Used to force compliance with the security policy and practices
within the organization
▪ Preventive
● Seeks to prevent or stop an attack from even occurring
▪ Recovery
● Used to recover a device after an attack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Gap Analysis

A

▪ Compares the current performance of the organization’s security posture to the desired security posture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly