For each of these classes, there are four types of controls: Preventive (Deterre
ID: 2529766 • Letter: F
Question
For each of these classes, there are four types of controls:
Preventive (Deterrent)
Detective
Corrective (Recovery)
Compensating
Please assign the correct Class of Security Control and Type of Control that match with the Security Control Listed below. It might be possible that multiple control classes or Control types could be an answer. It could also be None.
Security Control
Control Class:
A-Administration)
T-Technical
P Physical)
Control Type
P – Preventive
D – Detective
CR –Corrective
CM-Compensating
Security Awareness Training
Firewall
Anti-Virus
Hot Site
OS Upgrade
IDS (Intrusion Detection System)
System Monitoring
Backup Generator
System Monitoring
Security Guard
Motion Detector
Vulnerability Mitigation
2. Match he correct COBIT domains (
A - Planning and Organization,
B - Acquisition and Implementation,
C - Delivery and Support, and
D - Monitoring and Evaluation.
To the following to the following Control Objectives.
CONTROL OBJECTIVE
MATCHING COBIT DOMAIN
define the information architecture
assess risks
manage changes
ensure continuous service
assess internal control adequacy
install and accredit systems
obtain independent assurance
ensure compliance with external requirements
develop and maintain procedures
define a strategic IT plan
ensure systems security
manage the IT investment
manage human resources
identify and allocate costs
provide for independent audit
educate and train users
determine the technological direction
3) Write the correct NIST Security Control Class (Technical, Operational, or Management) for the given Security Control families and Identifiers
IDENTIFIER
FAMILY
CLASS
Risk Assessment
RA
Access Control
AC
Incident Response
IR
Maintenance
MA
Contingency Planning
CP
Personnel Security
PS
Media Protection
MP
Awareness and Training
AT
System and Services Acquisition
SA
Audit and Accountability
AU
Configuration Management
CM
Program Management
PM
System and Information Integrity
SI
Planning
PL
Identification and Authentication
IA
Security Control
Control Class:
A-Administration)
T-Technical
P Physical)
Control Type
P – Preventive
D – Detective
CR –Corrective
CM-Compensating
Security Awareness Training
Firewall
Anti-Virus
Hot Site
OS Upgrade
IDS (Intrusion Detection System)
System Monitoring
Backup Generator
System Monitoring
Security Guard
Motion Detector
Vulnerability Mitigation
Explanation / Answer
Answer - 1 Security Awareness Training A-Administration) P – Preventive Firewall T-Technical P – Preventive Anti-Virus T-Technical P – Preventive Hot Site T-Technical CM-Compensating OS Upgrade T-Technical CR –Corrective IDS (Intrusion Detection System) P-Physical P – Preventive System Monitoring A-Administration) D – Detective Backup Generator A-Administration) P – Preventive System Monitoring A-Administration) D – Detective Security Guard P-Physical P – Preventive Motion Detector T-Technical D – Detective Vulnerability Mitigation A-Administration) P – Preventive Answer - 2 CONTROL OBJECTIVE MATCHING COBIT DOMAIN define the information architecture A - Planning and Organization assess risks A - Planning and Organization manage changes D - Monitoring and Evaluation. ensure continuous service C - Delivery and Support assess internal control adequacy A - Planning and Organization install and accredit systems B - Acquisition and Implementation, obtain independent assurance B - Acquisition and Implementation, ensure compliance with external requirements B - Acquisition and Implementation, develop and maintain procedures B - Acquisition and Implementation, define a strategic IT plan A - Planning and Organization ensure systems security B - Acquisition and Implementation, manage the IT investment D - Monitoring and Evaluation. manage human resources C - Delivery and Support identify and allocate costs A - Planning and Organization provide for independent audit D - Monitoring and Evaluation. educate and train users C - Delivery and Support determine the technological direction D - Monitoring and Evaluation. Answer - 3 IDENTIFIER FAMILY CLASS Risk Assessment RA Operational Access Control AC Operational Incident Response IR Management Maintenance MA Management Contingency Planning CP Management Personnel Security PS Operational Media Protection MP Technical Awareness and Training AT Operational System and Services Acquisition SA Technical Audit and Accountability AU Operational Configuration Management CM Technical Program Management PM Technical System and Information Integrity SI Operational Planning PL Management Identification and Authentication IA Operational
Related Questions
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.