Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

For each of these classes, there are four types of controls: Preventive (Deterre

ID: 2529766 • Letter: F

Question

For each of these classes, there are four types of controls:

Preventive (Deterrent)

Detective

Corrective (Recovery)

Compensating

Please assign the correct Class of Security Control and Type of Control that match with the Security Control Listed below. It might be possible that multiple control classes or Control types could be an answer. It could also be None.

Security Control

Control Class:
A-Administration)
T-Technical
P Physical)

Control Type
P – Preventive
D – Detective
CR –Corrective
CM-Compensating

Security Awareness Training

Firewall

Anti-Virus

Hot Site

OS Upgrade

IDS (Intrusion Detection System)

System Monitoring

Backup Generator

System Monitoring

Security Guard

Motion Detector

Vulnerability Mitigation

2.     Match he correct COBIT domains (

         A - Planning and Organization,

        B - Acquisition and Implementation,

        C - Delivery and Support, and

        D - Monitoring and Evaluation.

To the following to the following Control Objectives.

CONTROL OBJECTIVE

MATCHING COBIT DOMAIN

define the information architecture

assess risks

manage changes

ensure continuous service

assess internal control adequacy

install and accredit systems

obtain independent assurance

ensure compliance with external requirements

develop and maintain procedures

define a strategic IT plan

ensure systems security

manage the IT investment

manage human resources

identify and allocate costs

provide for independent audit

educate and train users

determine the technological direction

3) Write the correct NIST Security Control Class (Technical, Operational, or Management) for the given Security Control families and Identifiers

IDENTIFIER

FAMILY

CLASS

Risk Assessment

RA

Access Control

AC

Incident Response

IR

Maintenance

MA

Contingency Planning

CP

Personnel Security

PS

Media Protection

MP

Awareness and Training

AT

System and Services Acquisition

SA

Audit and Accountability

AU

Configuration Management

CM

Program Management

PM

System and Information Integrity

SI

Planning

PL

Identification and Authentication

IA

Security Control

Control Class:
A-Administration)
T-Technical
P Physical)

Control Type
P – Preventive
D – Detective
CR –Corrective
CM-Compensating

Security Awareness Training

Firewall

Anti-Virus

Hot Site

OS Upgrade

IDS (Intrusion Detection System)

System Monitoring

Backup Generator

System Monitoring

Security Guard

Motion Detector

Vulnerability Mitigation

Explanation / Answer

Answer - 1 Security Awareness Training A-Administration) P – Preventive Firewall T-Technical P – Preventive Anti-Virus T-Technical P – Preventive Hot Site T-Technical CM-Compensating OS Upgrade T-Technical CR –Corrective IDS (Intrusion Detection System) P-Physical P – Preventive System Monitoring A-Administration) D – Detective Backup Generator A-Administration) P – Preventive System Monitoring A-Administration) D – Detective Security Guard P-Physical P – Preventive Motion Detector T-Technical D – Detective Vulnerability Mitigation A-Administration) P – Preventive Answer - 2 CONTROL OBJECTIVE MATCHING COBIT DOMAIN define the information architecture A - Planning and Organization assess risks A - Planning and Organization manage changes D - Monitoring and Evaluation. ensure continuous service C - Delivery and Support assess internal control adequacy A - Planning and Organization install and accredit systems B - Acquisition and Implementation, obtain independent assurance B - Acquisition and Implementation, ensure compliance with external requirements B - Acquisition and Implementation, develop and maintain procedures B - Acquisition and Implementation, define a strategic IT plan A - Planning and Organization ensure systems security B - Acquisition and Implementation, manage the IT investment D - Monitoring and Evaluation. manage human resources C - Delivery and Support identify and allocate costs A - Planning and Organization provide for independent audit D - Monitoring and Evaluation. educate and train users C - Delivery and Support determine the technological direction D - Monitoring and Evaluation. Answer - 3 IDENTIFIER FAMILY CLASS Risk Assessment RA Operational Access Control AC Operational Incident Response IR Management Maintenance MA Management Contingency Planning CP Management Personnel Security PS Operational Media Protection MP Technical Awareness and Training AT Operational System and Services Acquisition SA Technical Audit and Accountability AU Operational Configuration Management CM Technical Program Management PM Technical System and Information Integrity SI Operational Planning PL Management Identification and Authentication IA Operational