Security Controls

Scenario

As a security consultant at an IT company, your role is to determine which would be the best security controls to put in place. While organisations cannot realistically plan for every possible attack, it is important to consider the potential risks and apply the best security controls for different scenarios. Your task is to identify the best security controls to put in place for each situation described below.

Scenario 1

IT Admin: The last attack caused real damage. We need systems that immediately detect suspicious activity on our network.

Scenario 1 Explanation

Scenario 1 needs a Technical control. Technical controls encompass the organization's hardware and software, such as operating systems and security appliances. It also needs a Detective functional type. Detective controls identify and record attempts or successes with regard to intrusions or attacks. A prime remediation for this scenario would be deploying an IDS/IPS.

Scenario 2

CEO: Our employees are visiting unsafe websites often. Have we even told them they shouldn't be doing that?

Scenario 2 Explanation

Scenario 2 needs an Operational control. Operational controls relate to processes, policies, and procedures. IT also needs a Directive functional type. Directive controls provide guidelines, rules, or expectations for behavior. A prime remediation for this scenario would be creating an acceptable use policy.

Scenario 3

CIO: Anyone can walk into the server room. We need to restrict access to only authorized personnel.

Scenario 3 Explanation

Scenario 3 needs a Physical control. Physical controls protect the physical access to systems and areas. It also needs a Preventative functional type. Preventative controls stop unwanted or unauthorized actions before they occur. A prime remediation for this scenario would be installing biometric access control.