From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Access control

Access control

- In order to protect our information, we're going to utilize various types of access control. Now, access control measures are broken down into seven different categories. These are compensative, corrective, detective, deterrent, directive, preventive, and recovery. Let's take a look at each of these categories. First, we have compensative access controls, and these are going to be used in place of a primary access control measure in order to mitigate a given risk. These controls can be deployed to enforce and support a security policy. For example, we might require that two system administrators perform a certain action, like downloading a copy of the database to an external device. That way, we can minimize the risk of a trusted insider stealing that information. This mitigation is based on a policy of dual control, which might be considered an administrative control if you think back to our discussion of policies earlier on in the course. Now, second, corrective access controls…

Contents