Cyberstudy
PDF p.18 In progress

Security Control Categories

Open PDF at p.18 13 flashcards

Summary

PDF p.18

Security controls ensure that systems and data assets maintain confidentiality, integrity, availability, and non-repudiation. These controls are categorized into managerial, operational, technical, and physical, each addressing different aspects of security implementation.

In plain words

Supplementary — not from your PDF

Controls are grouped by how they are put in place. Managerial controls provide oversight, such as risk assessments. Operational controls are carried out by people. Technical controls are hardware, software or firmware. Physical controls protect buildings and equipment.

Detailed explanation

PDF p.18
  • Security Controls
    • Purpose: Provide systems and data assets with confidentiality, integrity, availability, and non-repudiation.
    • Categories
      • Managerial: Oversight and evaluation.
      • Operational: Implemented by people.
      • Technical: Implemented as systems.
      • Physical: Deter and detect physical access.
  • Managerial Controls
    • Definition: Provide oversight of the information system.
    • Examples: Risk identification, evaluation tools for selecting other controls.
  • Operational Controls
    • Definition: Implemented primarily by people.
    • Examples: Security guards, training programs.
  • Technical Controls
    • Definition: Implemented as hardware, software, or firmware.
    • Examples: Firewalls, antivirus software, OS access control models.
  • Physical Controls
    • Definition: Deter and detect access to premises and hardware.
    • Examples: Security cameras, alarms, gateways, locks, lighting, security guards.

Important terms

taken from the text above
Managerial
Oversight and evaluation.
Operational
Implemented by people.
Technical
Implemented as systems.
Physical
Deter and detect physical access.
Managerial Controls
Provide oversight of the information system.
Operational Controls
Implemented primarily by people.
Technical Controls
Implemented as hardware, software, or firmware.
Physical Controls
Deter and detect access to premises and hardware.

Examples & real-world scenarios

Supplementary — not from your PDF
  • Managerial: an annual risk assessment used to choose other controls.
  • Operational: security awareness training delivered by staff.
  • Technical: a firewall rule that blocks inbound Telnet.
  • Physical: a badge reader on the server-room door.

Scenario

An auditor asks for one control from each category. You show the risk register (managerial), the guard patrol schedule (operational), the antivirus management console (technical) and the cameras at the data-center entrance (physical).

Common mistakes

Supplementary — not from your PDF
  • Confusing categories (how a control is implemented) with functional types (what it does, such as preventive or detective). A firewall is technical by category and preventive by type.
  • Thinking a control fits only one category. The guide lists security guards under both operational and physical.

Practical skills

Supplementary — not from your PDF
  • Give each control two labels: its category and its functional type.

What I should remember

Key Points PDF p.18
  • Security Controls
    • Purpose: Ensure confidentiality, integrity, availability, non-repudiation.
    • Categories: Managerial, operational, technical, physical.
  • Managerial Controls
    • Oversight: Risk identification, evaluation tools.
  • Operational Controls
    • People-Based: Security guards, training programs.
  • Technical Controls
    • System-Based: Firewalls, antivirus software, OS access control models.
  • Physical Controls
    • Access Deterrence: Security cameras, alarms, gateways, locks, lighting, security guards.