In-Place Controls
Planned Controls
Policies & Procedures
Technical Controls
Physical Controls
100

controls

What are countermeasures?

100

Access Controls (AC)

What is a Control Family?

100

Procedures performed by people

What are procedural controls? 

100

Technical controls

What are tools that automate protection?

100

Protects the physical environment

What is a physical control? 

200

Prevent, recover & detect

What are objectives of controls? 

200

NIST Controls

What is NIST SP 800-53?

200

Written documents that provide guidelines and rules for the organization. 

What are policies and procedures? 

200

Session time out

What is an technical control that ensures that an unauthorized user doesn't have access w/out providing their credentials? 

200

Locks

What is the simplest method of physical security?

300

Installed inside the operating system

In-Place Control

300

Planned Controls

What is approved but not installed yet? 

300

Backup Policy

What states that backups need to be performed but does not tell you how to perform them.

300

Log

What record includes who, what, where, when?

300

Gas system

What is a primary way to fight a Class C fire?

400

Control does not meet an objective (prevent,recover,detect)

When a control should be replaced? 

400

Controls covering all aspects of security incidents 

What are incident response controls?

400

Vulnerability Scanning Procedures

What are procedures that specify how the scans are to be documented and reported?

400

Port 80

What is the well-known port for HTTP?

400

Proximity card

What can an attacker put in a paper bag to gather credit card data by riding up and down the elevator all day long. 

500

Replace the anti-virus software

What action should you take when a system has been infected?

500

They provide nonrepudiation

What are digital signatures?

500

Business Continuity Plan

What is a comprehensive plan that helps organizations plan for an emergency?

500

Changes plaintext data into ciphered data

What is encryption? 

500

Three - barrier protection 

What is a main entrance, secure employee area and secure computer area?

M
e
n
u