From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Security controls

Security controls

- In this video, we're going to talk about security controls. Now, we spend a lot of time talking about risk, ways to mitigate it, and the security controls that we can add to prevent risk from being realized in our operational networks. But if we never review or test our security controls, our organizations can be extremely vulnerable. As information system security professionals, we spend much of our day reviewing all aspects of security, including device configurations, policies, procedures, and patch levels of our systems, in addition to continually conducting security training. In addition to these self-conducted reviews, we're also subject to outside audits, vulnerability tests, and pen tests too. All of these security control reviews will help make our networks more secure and should be conducted at least annually. Now, when you're reviewing security controls, you should consider the following questions. What security controls are in use? How can we improve these controls? Are…

Contents