TechKnowSurge
CompTIA Security+ 1.1 ISC2 CISSP 3.3 NIST 800-53 PL-10 NIST NICE K1212 CompTIA SecurityX 1.2
VideoSecurityFree

Risk Mitigation and Controls

Security controls are countermeasures organizations put in place to reduce or transfer risk, and they are classified by both category and functional type. The four control categories are managerial, operational, technical, and physical, while control types include preventative, deterrent, detective, corrective, recovery, compensating, and directive.

Complete this video to capture a CTF flag worth 1 point.

About this video

Security controls are countermeasures put in place to reduce or transfer risk within an organization. When a risk cannot or should not be avoided or simply accepted, implementing a control is the primary mechanism for managing its impact. Controls fall into four distinct categories based on how they are applied: managerial, operational, technical, and physical. Managerial controls consist of high-level policies, such as acceptable use agreements, that define the standards by which an organization operates. Operational controls govern everyday processes and procedures, such as structured onboarding checklists that ensure new employees complete required security training and account setup. Technical controls involve hardware or software solutions deployed to protect systems and networks, with firewalls being a common example. Physical controls address tangible, real-world security measures such as access-controlled doors for network closets or perimeter fencing around facilities. Beyond categories, controls are also defined by their functional type, which describes the role they play in the risk management lifecycle. Preventative controls stop an incident from occurring in the first place, while deterrent controls discourage harmful actions without necessarily blocking them outright. Detective controls, such as security cameras or monitoring systems, identify and record events as they happen or after the fact, enabling a response. Corrective controls are activated during an incident to contain damage, such as severing a compromised database connection, whereas recovery controls restore normal operations once the threat is resolved. Compensating controls offset residual risk through alternative means, such as carrying insurance, and directive controls mandate specific actions or configurations based on policy or regulatory requirements. It is important to note that a single control can serve multiple functional types at once; a clearly visible security camera, for example, simultaneously acts as a deterrent, a detective tool, and potentially a directive measure depending on applicable compliance requirements.

What you'll learn

What's covered

Security Controls

Aligned to

CompTIA Security+
1.1 Compare and contrast various types of security controls.
ISC2 CISSP
3.3 Select controls based upon systems security requirements
NIST 800-53
PL-10 Baseline Selection
NIST NICE
K1212 Knowledge of security controls
CompTIA SecurityX
1.2 Given a scenario, implement the appropriate risk management strategies, policies, and controls.

Key terms

Security Control
Any safeguard or countermeasure — whether technical, physical, or administrative — implemented to protect the confidentiality, integrity, and availability of systems and data. Security controls are classified by function (preventative, detective, corrective) and type (technical, physical, administrative).
Managerial Control
A security control focused on managing the security program, including risk assessments and overarching risk management activities.
Operational Control
A security control based on procedures and processes that guide day-to-day business functions to maintain security.
Technical Control
A security control implemented through technology — such as firewalls, antivirus software, encryption, or access control systems — rather than through physical measures or administrative policies.
Physical Control
A security control that protects assets through tangible, real-world measures — such as locks, security cameras, mantraps, fences, and safes — to prevent unauthorized physical access or tampering.
Preventative Control
A security control designed to stop a threat or incident from occurring in the first place. Firewalls, encryption, and access control policies are common examples of preventative controls.
Deterrent Control
A security control that discourages threat actors from attempting an attack by making the environment appear more difficult or risky to compromise. Warning banners, visible cameras, and security signage are common deterrent controls.
Detective Control
A security control that identifies and alerts on security incidents or anomalous activity as they occur or after the fact. Intrusion detection systems, security logs, and audit trails are examples of detective controls.
Corrective Control
A security control that addresses and remediates a security incident after it has been identified — such as restoring systems from backup, patching a exploited vulnerability, or blocking an attacker's IP address.
Compensating Control
An alternative security measure implemented to offset a known risk or vulnerability when a primary control cannot be fully applied. A compensating control must provide an equivalent or greater level of protection.
Directive Control
A security control mandated by laws, regulations, or customer requirements that an organization must implement with no discretion. Examples include legally required data retention policies and mandatory breach notification procedures.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.

Topics

Security Controls Risk Mitigation Control Categories Control Types Cybersecurity

Transcript

When we have some sort of risk, we can put a control into place to mitigate that risk. There's several different types and categories of controls.

In another lesson I talk about strategies when dealing with risk. We could either avoid the risk, by maybe not doing a project because it's too risky, or we could accept the risk and just understand that it's part of what we're doing — we're accepting that risk and not doing anything about it. Or we could reduce the impact, or transfer the risk. If we're doing this, what is happening is we're putting a control into place in order to reduce the impact or transfer the risk. That control right there has several different types of controls and several different control categories.

By definition, a control is just countermeasures that we're taking to reduce risk. Some control examples might be, to reduce the impact if data were to be stolen, to only keep certain data for a certain period of time. Or to transfer: maybe we're looking at insurance to be able to transfer the risk to some sort of other entity. So these are controls that we put into place to reduce the amount of risk.

Control categories

Controls can be categorized in several different categories. One is managerial. These are going to be our high-level policies that we operate by. For instance, an acceptable use policy, which we may make our user sign. That's going to be a policy that sets the tone for how we're going to operate.

Then we have the operational. This is the actual day-to-day, how we carry out our functions. So for instance, maybe we built security measures into our onboarding process. In that onboarding process maybe there's a checklist that we follow, so that when somebody is brought on to the company they have to go through certain things to be onboarded, to make sure they have the proper security training and make sure that they have the proper account set up and everything is set up in a proper way. So those are the checklists that we follow and the procedures that we follow.

Then we have the technical aspect. The technical aspect is going to be equipment, whether it's software or hardware, that we implement from a technology standpoint. A good example of this might be a software or hardware firewall that we set up. It's a technology that we set up to guard our networks.

Then there's the physical aspect. This is perhaps security measures where we have door accesses before they can get into our network closet, or perhaps it's also fencing around the building that we have. So we put up physical controls.

Control types

There are also several different types of controls. One of them is preventative. Preventative prevents something from happening — that you're not capable of following through with something, or making something happen, because it's just going to stop you. For instance, a firewall will stop you from gaining access into the network.

Then there's a deterrent. That's something like a fence. Somebody could climb over a fence, but it's unlikely that most people are going to climb over a fence, so that's going to deter them from that action.

Or maybe it's detective, something like a security camera where we are going to monitor. So if something does happen we can take action on it — that's detective. Or after the fact, if something did happen we can go back and look at the security tapes to see what happened.

Then there's corrective. This is, if something were to happen, what are we going to do to correct the situation. For instance, maybe our network is being attacked, and so maybe we cut some sort of connectivity off so they no longer have access to that network until we solve whatever problem it is. Maybe we're concerned about our database and some sort of information that's exposed out there, so we cut off connection to that database so that way it's not exposed. So that would be a corrective.

And then there's the recovery. At some point in time we need to bring that database back online, so we need to solve what the issue is and go through the recovery of that, and so we can bring it back online.

Then we have compensating. Compensating is, if you have an issue you can compensate it with something else. An insurance plan would be an example of this: we're going to compensate some sort of risk by bringing on an insurance company, so it lessens that risk. If it were to happen, then we'd have some reimbursement there.

Or directive — then that's something that we just have to do.

One control, several categories

Once again, what happens is that we could actually have a control that meets more than just one of these categories. For instance, a really apparent video camera that's videoing or surveying an area — video surveillance could be considered a deterrent, because somebody might not want to climb that fence because there's a camera right there and it would expose who climbed that fence. But it's also detective, where we can go back and look at it or monitor the area, so it could follow. And it also could be directive too, I guess, because we could be directed that you have to have security cameras for the certain type of business that we're doing. So these are different types.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →