Security controls are countermeasures organizations put in place to reduce or transfer risk, and they are classified by both category and functional type. The four control categories are managerial, operational, technical, and physical, while control types include preventative, deterrent, detective, corrective, recovery, compensating, and directive.
Security Controls
When we have some sort of risk, we can put a control into place to mitigate that risk. There's several different types and categories of controls.
In another lesson I talk about strategies when dealing with risk. We could either avoid the risk, by maybe not doing a project because it's too risky, or we could accept the risk and just understand that it's part of what we're doing — we're accepting that risk and not doing anything about it. Or we could reduce the impact, or transfer the risk. If we're doing this, what is happening is we're putting a control into place in order to reduce the impact or transfer the risk. That control right there has several different types of controls and several different control categories.
By definition, a control is just countermeasures that we're taking to reduce risk. Some control examples might be, to reduce the impact if data were to be stolen, to only keep certain data for a certain period of time. Or to transfer: maybe we're looking at insurance to be able to transfer the risk to some sort of other entity. So these are controls that we put into place to reduce the amount of risk.
Controls can be categorized in several different categories. One is managerial. These are going to be our high-level policies that we operate by. For instance, an acceptable use policy, which we may make our user sign. That's going to be a policy that sets the tone for how we're going to operate.
Then we have the operational. This is the actual day-to-day, how we carry out our functions. So for instance, maybe we built security measures into our onboarding process. In that onboarding process maybe there's a checklist that we follow, so that when somebody is brought on to the company they have to go through certain things to be onboarded, to make sure they have the proper security training and make sure that they have the proper account set up and everything is set up in a proper way. So those are the checklists that we follow and the procedures that we follow.
Then we have the technical aspect. The technical aspect is going to be equipment, whether it's software or hardware, that we implement from a technology standpoint. A good example of this might be a software or hardware firewall that we set up. It's a technology that we set up to guard our networks.
Then there's the physical aspect. This is perhaps security measures where we have door accesses before they can get into our network closet, or perhaps it's also fencing around the building that we have. So we put up physical controls.
There are also several different types of controls. One of them is preventative. Preventative prevents something from happening — that you're not capable of following through with something, or making something happen, because it's just going to stop you. For instance, a firewall will stop you from gaining access into the network.
Then there's a deterrent. That's something like a fence. Somebody could climb over a fence, but it's unlikely that most people are going to climb over a fence, so that's going to deter them from that action.
Or maybe it's detective, something like a security camera where we are going to monitor. So if something does happen we can take action on it — that's detective. Or after the fact, if something did happen we can go back and look at the security tapes to see what happened.
Then there's corrective. This is, if something were to happen, what are we going to do to correct the situation. For instance, maybe our network is being attacked, and so maybe we cut some sort of connectivity off so they no longer have access to that network until we solve whatever problem it is. Maybe we're concerned about our database and some sort of information that's exposed out there, so we cut off connection to that database so that way it's not exposed. So that would be a corrective.
And then there's the recovery. At some point in time we need to bring that database back online, so we need to solve what the issue is and go through the recovery of that, and so we can bring it back online.
Then we have compensating. Compensating is, if you have an issue you can compensate it with something else. An insurance plan would be an example of this: we're going to compensate some sort of risk by bringing on an insurance company, so it lessens that risk. If it were to happen, then we'd have some reimbursement there.
Or directive — then that's something that we just have to do.
Once again, what happens is that we could actually have a control that meets more than just one of these categories. For instance, a really apparent video camera that's videoing or surveying an area — video surveillance could be considered a deterrent, because somebody might not want to climb that fence because there's a camera right there and it would expose who climbed that fence. But it's also detective, where we can go back and look at it or monitor the area, so it could follow. And it also could be directive too, I guess, because we could be directed that you have to have security cameras for the certain type of business that we're doing. So these are different types.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →