Untitled Studyset
Created by 0quietwinds0
Administrative controls focused on policy, strategy, governance, and risk management.
Control Categories - Managerial
| Term | Definition |
|---|---|
Administrative controls focused on policy, strategy, governance, and risk management. | Control Categories - Managerial |
Controls implemented by people to carry out security processes. | Control Categories - Operational |
Controls implemented using technology (hardware, software, firmware). | Control Categories - Technical |
Controls that protect the physical environment where systems and data are located. | Control Categories - Physical |
Function: Proactively stops an incident from occurring. | Control Types - Preventive |
Function: Identifies that an incident has occurred or is in progress | Control Types - Detective |
Function: Remediates or fixes a system after an incident has occurred. | Control Types - Corrective |
Function: Discourages a potential attacker from attempting an attack. | Control Types - Deterrent |
Function: A backup control that provides an alternative when primary control is not feasible. | Control Types - Compensating |
Function: An administrative control that provides guidance on expected behavior | Control Types - Directive |
A formal process for making changes to IT systems to minimize risk and service disruption. | Change Management |
Approval Process, Impact Analysis, Backout Plan, Maintenance Window, Version Control. | Change Management - Key Process |
A user account logs in from New York and then, two minutes later, logs in from Moscow. | Indicator of Compromise (IoC) - Impossible Travel |
A single user account being actively used from multiple IP addresses simultaneously. | Indicator of Compromise (IoC) - Concurrent Session |
A user account logging in and downloading massive amounts of data at 3:00 AM on a Sunday. | Indicator of Compromise (IoC) - Off-Hours Usage |
A security policy that only permits pre-approved applications to run, blocking all others by default. | Mitigation Technique - Application Allow List |
The formal process of taking a server or application out of service and ensuring all data is securely wiped. | Mitigation Technique - Decommissioning |
The process of reducing a system's overall attack surface (e.g., disabling unnecessary ports). | Mitigation Technique - Hardening Techniques |
Dividing a larger network into smaller, isolated subnets (VLANs). | Mitigation Technique - Network Segmentation |
The most effective mitigation against social engineering by training employees to recognize threats. | Mitigation Technique - User Awareness Training |