Network security controls are categorized by their function—preventing, deterring, detecting, correcting, recovering from, compensating for, or directing responses to risk. Understanding each control type and how they can overlap is essential for building a layered security strategy.
Network Security Controls
There are different types of controls that we can implement on our network to accomplish different things. Here are the different types of controls that we can put into place to mitigate against risk to the organization.
One of them is preventative. Preventative will stop something from happening. So if we have some sort of issue, a preventative measure would just stop it from being an issue at all. One example of this would be access control to certain data on our network. If we put access control in place, then that's going to prevent certain people from gaining access to that data.
A deterrent doesn't stop an action from happening, but it's going to make it a lot harder for something to happen, and hopefully to the point where somebody's not going to want to take those steps to make it happen. So if an attacker is trying to get into the network, they're not going to want to get into it. A good example of this is a cyclone fence. I'm not one to go and climb a cyclone fence to get to the other side. If there's a gate, maybe I would go through it, but if there's a fence, I'm probably not going to climb over it. But could I? Of course. I used to do that as a kid all the time, would climb over these cyclone fences. It's pretty easy to do.
Then we have detective. Detective doesn't stop or deter something from happening, but if it does happen, we can detect that it did happen. Surveillance cameras is an example of detective, that we're putting it up to detect if something is happening, and we can monitor this, or after the fact we can go back and look at it. Same thing with log files of a server: we could go back and look at them and see what's happening on there to detect if something's been compromised.
The video cameras also could be considered a deterrent, right? Like a lot of times people will see a security camera and then not want to break the law or climb a fence or do whatever the case may be, because there is a security camera. So it could fall in more than once, but one of the examples here is detective.
There are also corrective controls. These are the controls that we put into place to stop something from happening if it's happening. One example might be, if a hacker is breaking into our network, then we can unplug the network so that way it's no longer at risk. Of course, we still have an issue here that we need to fix, but this is the corrective action to stop the hacking from happening.
Once we stop that hacker from hacking our network, because we unplugged the network, we still have a problem — we still have a down network. So we need to fix the issue and get it back online. This is the recovery control. One recovery that we may have to use is backup. So we might have to grab those tape backups or those online backups and do a restore.
Maybe there's a vulnerability that we're concerned about and we really haven't found a way to prevent it. So one more thing that we can do is a compensating control. One example of a compensating control might be something like insurance, that we take out insurance on a risk. Another example might be, if somebody's on call and they can't for some reason do the troubleshooting that we need them to do, maybe we have a backup on-call person, somebody that could step in in case that primary one isn't able to show up and do the troubleshooting.
Then there is the directive, something that we have to do. Directive could be something that we are directing our employees that they have to follow and do, or it could be something that's directed to the company or organization. For instance, let's say that there's some sort of regulatory compliance that we have to comply to. Directive controls are there for a reason.
If it's a directive control, it probably also falls into one of these categories. They're not mutually exclusive; that is, you can have something that is part of multiple categories here. One example of that is the acceptable use policy, something that we have others sign so that way we make sure that they're in agreeance to what their behavior should be on our network. You could argue that this would be a deterrent, that they're not going to have those certain behaviors, or you could argue that it's preventative, because they're not going to have that certain behavior that would put your network at risk or your organization at risk. So really, if you see this on the test, you probably should mark preventative — at least that's what my sources say.
So here's a question for you: what type would log files be? And the answer to it is it's detective, that we're able to go back afterwards and see what the logs are and see what has happened on that server, to be able to detect what is going on on that server. And the same thing with a SIEM, a security information and event management system. What happens is these log files get ported into the SIEM, and it allows it to do some analysis across multiple systems to see what's going on on our network, and even start alerting us because it's doing that.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →