6 TECHNICAL SECURITY CONTROLS

In this chapter the technical controls that are implemented to provide protection against security incidents are discussed in more detail. This includes the detection, prevention and mitigation of such incidents.

As discussed in the previous chapter, there are three main types of operational control:

  • Procedural – for example checking references for job applicants.
  • Product/technical – for example passwords or encryption.
  • Physical – for example locks on doors and secure cabinets.

Of these, the product and technical operational controls are perhaps the most important in terms of information security since they are often the last barrier to illegal or unauthorised activity. As mentioned previously, this book deals ...

Get Information Security Management Principles, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.