What Controls?
Even More Controls?
We put the Fun in Fundamentals
Ch Ch Changes
xxxx-xxxx-xxxx-1234
100

Firewalls are a typical implementation of this kind of security control category

What is a Technical security control?

100

Encryption is a technical control category, but is an example of this category of security control type

What is a Preventative security control?

100

This proves I did what I did

What is Non-Repudiation?

100

This is a contingency plan in case a change does not go as planned or has unforeseen consequences

What is a Backout Plan?

100

This system enables secure communication and encryption without needing to share private keys

What is PKI Public Key Infrastructure?

200

This type of control category focuses on policies, procedure, and strategies for security

What is a Managerial Control?

200

Warning signs, guidelines, or other procedures designed to guide users toward desired security behaviors is an example of this type of security control function.

What is Directive?

200

This shows the difference between where security measures are and where they are desired to be, usually for regulatory compliance

What is a Gap Analysis?

200

This refers to the numbering of software, used to track what software is being used and to ensure that systems are running the expected software

What is Version Control?

200

This is the method of hiding data within another piece of data, can be detected through hashing if you have a known original version of the data

What is Steganography?

300

Wilma was tasked with evaluating entryways to see if bollards are appropriate. She determines that bollards are useful and recommends them to the CSO and is told that she can contact a contractor to get quotes. Bollards are an example of this kind of security control category.

What is Physical security control?

300

This is how a detective security control achieves it's function

What is identify events as they occur, examples include IDS, audits, log monitoring?

300

This is the idea that you always verify identity and authentication factors before accepting a connection or anything else

What is Zero Trust?

300

This is the biggest and often most costly downside to the implementation of changes in most scenarios, assuming there are no issues stemming from the change itself

What is Downtime?

300

This is the method of using a substitute piece of data that can be linked internally to a sensitive piece of data, like a credit card number or health information, to protect that data while it is in transit.

What is Tokenization?

400

Using an Incident Response Plan is an example of this kind of security control.

What is Operational security control?

400

An Incident Response plan fits in an operational control category but serves this functional security role.

What is a Corrective security control?

400

This is the last thing you should do when writing an ACL, especially if you know that it is not automatically added.

What is writing an Implicit Deny?

400

This should be performed to understand the short and long term security implications of a change on the business before it is implemented, used to understand the potential risks of a change

What is a Business Impact Analysis?

400

This resource from a CA tracks certificates that are no longer valid before their expiration date due to compromise, loss, or other security concerns, often safely accessed by going to a Certificate Distribution Point specified in certificates issued by that CA.

What is a CRL Certificate Revocation List?

500

A risk assessment is an example of this kind of security control category.

What is a Managerial security control?

500

To fulfill a specific data protection mandate while transitioning away from an obsolete database infrastructure, an organization implements an inline network scanner that automatically redacts out-of-bound strings because the target legacy code cannot natively execute data loss prevention filters.

What is a Compensating security control type?

500

These are used to attempt to understand the behavior of a malicious actor on a single host with no production data on it

What is a Honeypot?

500

These are stated so that users and customers know when to expect systems to be offline for a change

What is a Maintenance Window? 

500

This security method is demonstrated in the title of this column

What is Obfuscation or Masking?