Control Objectives 2 Flashcards

1
Q

Directive controls

A

Are proactive actions taken to cause or encourage a desirable event and outcome occur. Are broad in nature, used to increase the effectiveness of other controls, examples: frameworks, models, polices, guidance statements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Control category - operational

A

Operational controls are aligned with a process that are primaily implemented and executed by people (change management, testing, training)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Control classification- corrective

A

Corrective controls minimize the impact of a threat agent or modify or fix situation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Control category- technical

A

Technical control mechanism are implemented using hardware, software and/or firmware components, can be native or supplementary (firewalls, cryptography, 2FA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Control classification - preventive

A

Preventive controls stop a threat agent from being successful

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Layered security

A

Layered security (defense-in-depth) is the design and implementation of multiple overlapping layers of diverse controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Control category-Managerial

A

Managerial controls relate to risk management, governance, oversight, strategic alignment and decision making

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Control category physical

A

Physical controls are designed to address physical interactions. Generally related to buildings and equipment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Control classification : Deterrent

A

Deterrent controls discourage a threat agent from acting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Control classification : Detective controls

A

Detective controls identify and report a threat agent or a threat action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Compensating controls

A

Compensating controls are implemented in lieu of a recommended control that provided equivalent or comparable protection, can be supplemental, short-term or temporarly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly