real security controls Flashcards

(17 cards)

1
Q

how many different security risks are out there

A

many different categories and types

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what are the different assets are there

A

data
physical property
computer systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

purpose of security controls

A

minimize the impact & limit the damage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

technical controls

A

controls implemented using systems

operating system controls

firewalls. antivirus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

managerial controls

A

administrative controls associated with security design and implementation

security policies, SOPs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

operational controls

A

controls implemented by ppl instead of systems

security guards, awareness programs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

physical controls

A

limit physical access

guard shack

fence

lock

badge readers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what are the control categories

A

technical

managerial

physical

operational

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what are the control types

A

preventive

deterrent

detective

corrective

compensating

directive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

preventive

A

block access to source

you shall not pass

prevent access
- firewall rules - technical
- follow security policy - managerial
- guard checks all identification - operational
- enable door locks - physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

deterrent

A

discourage an intrusion attempt

does not directly prevent access

make an attacker think twice
- application splash screens = technical
- threat of demotion = managerial
- front reception desk = operation
- posted warning signs = physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

detective

A

identify and log an intrusion attempt

may not prevent access

find the issue
- collect and review system logs
- regularly patrol the property
- enable motion detectors
- review login reports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

corrective

A

apply a control after an event has been detected

reverse the impact of an event

continue operating without minimal downtime

correct the problem
- restoring from backups can mitigate a ransomware infection
- create policies for reporting security issues
- contact law enforcement to manage criminal activity
- use a fire extinguisher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

compensating

A

control using other means

existing controls aren’t sufficient

may be temporary

prevent the exploitation of a weakness
- firewall blocks a specific application instead of patching the app - technical
- implement a separation of duties - managerial
- require simultaneous guard duties - operational
- generator used after power outage - physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

directive

A

direct a subject towards security compliance

a relatively weak security control

do this, please
- store all sensitive files in a protected folder - technical
- create compliance policies and procedures - managerial
- train users on proper security policy - operational
- post a sign for “authorized personnel only” - physical

17
Q

managing security controls

A

these are not inclusive lists

there are many categories of control

some organizations will combine types

there are multiple security controls for each category and type
- some security controls may exist in multiple types or categories
- new security controls are created as systems and processes evolve
- your organization may use very different controls