Security Controls - CompTIA Security+ SY0-701 - 1.1 Flashcards
security plus (16 cards)
Technical controls
Controls using systems
operating system controls
Fire walls/anti-virus
Managerial controls
admin controls that go with security design/implementation
security polices/stand op procedurees
Operational controls
controls implemented by people instead of systems
Physical Controls
Limit physical access
guard shack
Fences, locks
badge readers
Preventive controls examples
technical=fire wall
managerial=on-boarding policy
operational=guard shack
Physical=door lock
Deterrent control
discourage an intrusion attempt
does not directly prevent access
Make an attacker think twice (Deterrent prt2)
app splash screen
threat of demotion
front desk reception
posted warning signs
Deterrent examples prt 3
Technical=splash screen
managerial=demotion
operational = reception desk
physical=warning signs
Detective control types
identify/log intrusion attempts
collect review system logs
login reports
patrol property
enable motion detectors
detective control examples
Technical = sys logs
managerial = review login reports
operational=property patrols
physical = motion detectors
Corrective controls types
apply a control after the vent has been detected
reverse the impact
continue operating with minimal downtime
corrective control examples
technical=restoring back ups mitigate a ransomware infection
managerial=polices for reporting issues
operational=contact authorities
physical =fire extinguisher
compensating control types
control using other means
existing controls aren’t sufficient
may be temporary
compensating control type examples
tech=firewall blocks specific apps
managerial=separation of duties
operational=require multiple security staff
physical = power generator
Directive control types
direct a subject towards a security compliance
a week security control
directive control examples
tech=store all sensitive files in a protected folder
managerial = compliance polices/procedures
operational=train users security policy
physical=sign “authorized personnel only”