Security Controls Flashcards
(10 cards)
Managerial
A category of security control that provides oversight of information systems. Examples could include risk identification or a tool allowing the evaluation and selection of other security controls.
Operational
A category of security control that is implemented by people. For example, security guards and training programs are operational controls.
Technical
A category of security control that is implemented as a system. For example, firewalls, antivirus software, and OS access control models are technical controls.
Physical
A category of security control that is implemented by hardware used to deter or detect, such as as alarms, gateways, locks, lighting, and security cameras.
Preventive
A type of security control that acts before an incident to eliminate or reduce the likelihood that an attack can succeed.
Detective
A type of security control that acts during an incident to identify or record that it is happening.
Corrective
A type of security control that acts after an incident to eliminate or minimize its impact.
Directive
A type of control that enforces a rule of behavior through a policy or contract.
Deterrent
A type of security control that discourages intrusion attempts.
Compensating
A security measure that takes on risk mitigation when a primary control fails or cannot completely meet expectations.