CH1 Flashcards
(14 cards)
Control plays a crucial role in minimizing vulnerabilities within an organization technical systems including computer networks, software, and data management.
Technical Control
Type of controls policies, procedures and practices by management to guide and direct the activities of indviduals and teams.
Mangerial Controls
This type of control revovles around the execution o fday to day activities and processes necessary for delivery goods and services. They involves managing operational procedures, ensuring adherence to quality standards, enhancing productivitiy and optimzing effiiciency.
Operational Controls
Controls are a critical aspect of overall security focusing on the protetion of a orgstangable assets, facilities and resources.
Physical Controls
Examples of Technical Controls
Performance Reviews, Risk Assesment
Examples of Operational Controls
Incident response procedure, security awareness training, user access magagement
Example of managerial controls
Perforamnce reviews, Risk assesment, code of conduct
Control Type - These controls are designed to prevent problems or risks from occurign in the first place. They focus of eliminating o minimzing potential threats before they cause harm
Example - Firewalls
Preventive Controls
Control type aim to discourage indivduals from engaging in undesirable behaviors or activities. They create a perception of risk or negative consequences to deter offenders
Example - Cameras, strong passwords
Deterrent Controls
Control type implemented to ID and detect problems or risks which have already occured. Help to uncover issues or anomalies promptly to initate actions
Examples - SIEM
Detective Controls
Control Type that is put in place to address a problem or risks after they have been ID’ed. Back up or recovery
Corrective Control
Control Type where alternative measure implment when primary controls are not feasible of sufficient. Help offset the limitation or Deficinies of other controls.
Expample - Extra layer of security
Compensation Controls
Control type that invovles providing spefici insturctions or guidleines to ensure compliance with policies, porceudres or regulations. They establish a clear framework for employees to follow
Directive Controls