G1 ImplementingControls
G1 ImplementingControls
Implementing Controls
to Protect Assets
CompTIA Security+
Get Certified Get Ahead
By Darril Gibson
• Buildings
• Server rooms
• Locks
– Physical locks
– Physical cipher locks
– Biometric locks
– Cable locks
GetCertifiedGetAhead.com © 2021 YCDA, LLC
Physical Security Controls
• Tailgating and access control vestibules
• Security guards
• Cameras
• Signage
• Drones
• Design weaknesses
• System sprawl
• Undocumented assets
• Vendor diversity
• Technology diversity
• Control diversity
• Vaults
• Faraday Cage
• Safes
Hot Aisle
• Card skimming
• Card cloning
• Dual supply
• Online backups
• Offline backups
GetCertifiedGetAhead.com © 2021 YCDA, LLC
Backups Types
• Full backups
– Fastest recovery time
• Differential backup
– Backs up all the data that has changed since the
last full or differential backup
• Incremental backup
– Backs up all the data that has changed since the
last full or incremental backup
• Image backup
• Copy backup
• Testing backup
• Hot site
– Includes personnel, equipment, software, and communications
capabilities of the primary site
– All the data is up to date
– Can take over for a failed site within an hour
– Most effective disaster recovery
solution for an alternate site
– Most expensive to maintain
GetCertifiedGetAhead.com © 2021 YCDA, LLC
Continuity of Operations Sites
• Cold site
– Has power and connectivity needed for COOP
activation, but little else
– Least expensive and hardest to test
• Warm site
– Compromise between a
hot site and a cold site
• Order of restoration
– Return least critical functions first
GetCertifiedGetAhead.com © 2021 YCDA, LLC
Disaster Recovery Plan (DRP)
• Part of BCP
• Includes a hierarchical list of critical systems
• Prioritizes services to restore after an outage
• Testing validates a DRP
• Recovered systems tested before returning to
operation
– Can include a comparison to baselines
• Simulations
– simple simulations to full-blown tests
GetCertifiedGetAhead.com © 2021 YCDA, LLC
Chapter 9 Summary
• Comparing Physical Security Controls