Untitled Deck Flashcards
(775 cards)
What are the four categories of security mechanisms?
Technical, Managerial, Operational, Physical
What is a Technical security mechanism?
Hardware or software used to manage access to resources and systems
Give an example of a Technical security mechanism.
Encryption, smart cards, passwords, biometrics, access control lists (ACLs), firewalls
What does Managerial security focus on?
Policies and procedures defined by an organization’s security policy
Provide an example of a Managerial security measure.
Policies, procedures, vendor management, hiring practices
What is the purpose of Operational security measures?
Ensure day-to-day operations comply with overall security
List two examples of Operational security procedures.
- Backup and recovery procedures
- Awareness training
What does Physical security aim to protect?
The facility and real-world objects
Name a type of Physical security mechanism.
Guards, mantraps, fences, lights, motion detectors
What is a Preventive security control?
Deployed to prevent or stop unwanted or unauthorized activity
Give an example of a Preventive security control.
Fences, locks, biometrics, alarm systems
What is the purpose of Deterrent security controls?
Discourage violation of security policies
List two Detective security controls.
- Security guards
- Intrusion detection systems
What measures are included in Corrective security controls?
Fixing vulnerabilities or mitigating damage after incidents
What is a Compensating security control?
Provides options to aid in enforcement of security policies
What do Directive security controls aim to do?
Guide behavior and enforce compliance with security policies
True or False: A single security control can be classified as multiple types.
True
What does the CIA Triad stand for?
Confidentiality, Integrity, Availability
Define Confidentiality in the context of security.
Ensures sensitive data is only accessible to authorized users
What is one method to maintain Confidentiality?
Encryption, access controls, passwords
What is the purpose of Availability in security?
Ensures systems and data are accessible to authorized users
List two strategies to enhance Availability.
- Backup and recovery
- Redundant Internet connections
What does Integrity ensure regarding information?
Keeps information correct and unaltered