TechKnowSurge
CompTIA Security+ 1.1 ISC2 CISSP 3.3 ISC2 CISSP 3.4 CompTIA SecurityX 1.2 CompTIA Security+ 1.2 ISC2 CISSP 2.6 NIST 800-53 PL-2
VideoSecurityFree

Controls

Security controls are the measures, safeguards, and procedures organizations put in place to reduce cybersecurity risk, and they can be understood through three distinct definitions depending on the context. They are also organized by category and type to address different aspects of an organization's security posture.

Complete this video to capture a CTF flag worth 1 point.

About this video

Security controls are the foundational building blocks of any cybersecurity program, but the term itself is used in several distinct ways across the industry. At its broadest, a control is any action, device, or procedure put into place to mitigate risk — the definition most commonly encountered in certification exams like CompTIA Security+ and in guidance from NIST. Under this view, anything from installing a firewall to enforcing a password policy qualifies as a control. A second usage treats controls as essentially synonymous with standards, as seen in frameworks like NIST 800-53, where controls define the expectations and requirements an organization is expected to satisfy. A third definition, common in compliance-driven environments like SOC 2, elevates controls beyond standards by requiring measurable, documented evidence that the organization is actively fulfilling its obligations — not just acknowledging them on paper. Controls are also organized into categories based on what they protect and how they operate. Physical controls cover tangible barriers and protections such as fences, locks, and access-controlled doors. Technical controls include tools like firewalls, intrusion detection systems, and security monitoring software. Operational controls govern the day-to-day procedures the broader organization follows to maintain security. Managerial controls focus on risk management activities such as risk assessments and the overall security program, though this category has seen less formal use in recent NIST guidance even as it continues to appear in certification curricula. Beyond categories, controls are also classified by functional type — including preventative, deterrent, detective, corrective, recovery, compensating, and directive — each serving a distinct role in a layered security strategy.

What you'll learn

What's covered

Security Controls

Aligned to

CompTIA Security+
1.1 Compare and contrast various types of security controls.
1.2 Summarize fundamental security concepts.
ISC2 CISSP
3.3 Select controls based upon systems security requirements
3.4 Understand security capabilities of Information Systems (IS)
2.6 Determine data security controls and compliance requirements
CompTIA SecurityX
1.2 Given a scenario, implement the appropriate risk management strategies, policies, and controls.
NIST 800-53
PL-2 System Security and Privacy Plans

Key terms

Security Control
Any safeguard or countermeasure — whether technical, physical, or administrative — implemented to protect the confidentiality, integrity, and availability of systems and data. Security controls are classified by function (preventative, detective, corrective) and type (technical, physical, administrative).
Physical Control
A security control that protects assets through tangible, real-world measures — such as locks, security cameras, mantraps, fences, and safes — to prevent unauthorized physical access or tampering.
Technical Control
A security control implemented through technology — such as firewalls, antivirus software, encryption, or access control systems — rather than through physical measures or administrative policies.
Operational Control
A security control based on procedures and processes that guide day-to-day business functions to maintain security.
Managerial Control
A security control focused on managing the security program, including risk assessments and overarching risk management activities.
Preventative Control
A security control designed to stop a threat or incident from occurring in the first place. Firewalls, encryption, and access control policies are common examples of preventative controls.
Detective Control
A security control that identifies and alerts on security incidents or anomalous activity as they occur or after the fact. Intrusion detection systems, security logs, and audit trails are examples of detective controls.
Corrective Control
A security control that addresses and remediates a security incident after it has been identified — such as restoring systems from backup, patching a exploited vulnerability, or blocking an attacker's IP address.
Compensating Control
An alternative security measure implemented to offset a known risk or vulnerability when a primary control cannot be fully applied. A compensating control must provide an equivalent or greater level of protection.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.

Topics

Security Controls Risk Management Nist Framework Compliance Soc 2 Cybersecurity

Transcript

What Is a Control?

One of the things that we want to implement on our network are controls, controls that help us implement security. But what is a control? The first thing that you have to understand with controls is that different people have different definitions and different viewpoints on what a control is. I've really rendered this down into three different definitions for it. Number one, anything that you do, anything that you implement, is a control that helps mitigate risk. Number two, it is pretty much the same thing as a standard. And number three, it's a standard, but it takes it to another level. Let's talk about those different definitions.

Here's definition number one, or perspective number one on this, and this is what you'll find in a certification like a Security+, or NIST defines it this way: it's any measure or safeguard you put into place to help cybersecurity. So it's the actions you take, it's the devices you implement, it's the procedures that you implement. Anything that you do is a control that you're putting in place to mitigate risk.

I've also often heard of controls and standards being used interchangeably. Something like NIST 800-53 is one example of this, where I've seen controls being used in place of what a standard is. It just sets up what the expectations are and lays out the standards that you are going to meet. So that's number two.

Definition number three is something that I see when it comes more towards compliance. For instance, this is like SOC 2: they have controls that you have in place, and what is it? It's some sort of measurable outcome. It's not just a standard, but you have to turn something over to prove that you've met that standard. So it's taking a standard to the next level by proving that you actually are doing it.

Control Categories

There are several different control categories, so we can categorize the different controls that we're putting into place.

Number one, we could be having physical controls. That's the fences and the doors and the different physical aspects that we're putting into place to protect our technology.

Then there's the technical. That's more of like, do we have a firewall, do we have an intrusion detection system, do we have software that's monitoring things.

We have the operational side of this. This is the procedures that we're following: what kind of procedures do we follow to do our day-to-day functions throughout the company.

And then you have the managerial. It's kind of like the operational — in fact, there's a lot of confusion between the operational and managerial. The managerial is more of like, are we doing the risk assessments, are we managing the risk side of things. So it's more of the security program side of this, versus the operational, which would be the rest of the business. Now, I don't know that there's necessarily a really clear line dividing this managerial and operational, so really managerial is not being used as much anymore. In fact, NIST has taken it away as something that they define as being a type of control, although you still see it in the Security+.

Control Types

We can also break down controls into different types, whether it's preventative, deterrent, detective, corrective, recovery, compensating or directive.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →