Chapter 1 Lesson 2 Part 2 Flashcards
(12 cards)
What are corrective measures?
Measures implemented to respond to and correct the effect of an incident or security breach
Corrective measures aim to minimize damage caused by security incidents.
What is an example of a corrective measure?
Backups and disaster recovery plans
These involve duplicating important files in a secure location for recovery purposes.
What is an Incident Response Plan?
A team swiftly responding to an emergency, including steps to contain, investigate, mitigate, and recover systems
This plan is crucial for effective incident management.
What does software patching entail?
Fixing a leaky roof before it causes more damage; keeping software up to date to close potential entry points for attackers
This is a key corrective control.
What are compensating controls?
Measures put in place to add an extra layer of protection when primary controls may be insufficient
They help mitigate risks when primary security measures fail.
What is an example of a compensating control?
Manual Security Reviews
These involve human experts analyzing for suspicious behavior that automated systems may have missed.
What is the purpose of increased user training as a compensating control?
Educates users on best practices to understand security policies, which can increase overall security
Training is essential for user awareness and threat recognition.
What does Multi-Factor Authentication provide?
An extra layer of security by adding a second layer of security
This method enhances the authentication process.
What are directive measures?
Measures that provide guidance and set expectations for security among an organization
These help establish a security framework within the organization.
What is a security policy?
A rulebook and playbook for maintaining a secure environment, including guidelines and best practices
Security policies are foundational for organizational security.
What role do training materials and awareness campaigns play in security?
They train users on recognizing phishing emails and understanding the importance of strong passwords
These campaigns are vital for user education.
What is the purpose of risk assessment and compliance audits?
Periodic health checks to ensure compliance with security regulations and standards
They help identify vulnerabilities and ensure adherence to best practices.