Security Controls
On this page
3.3 Security Controls
Suggested retrieval lesson: 20–30 minutes.
Recall first
- What is the difference between preventive, detective, and corrective controls?
- Classify MFA, an alert for impossible travel, and restoring a backup.
- Why do organizations use layered controls instead of one perfect control?
Commit before reading.
What a control does
A security control is a safeguard or countermeasure that reduces security/privacy risk by preventing, detecting, correcting, deterring, or directing behavior. Controls can be administrative/managerial, technical/logical, or physical. NIST SP 800-53 presents a flexible catalog of security and privacy controls to be selected and tailored according to organizational risk; it is a supplement, while textbook lists and classifications may use different labels. NIST SP 800-53 Rev. 5
The exam-critical timing classification
- Preventive: acts before or during an unwanted event to stop it or reduce its chance. Examples: MFA, least privilege, secure configuration, input validation, network segmentation, security awareness, door locks.
- Detective: identifies an event or condition after it occurs or while it is occurring. Examples: audit logs, intrusion detection, file-integrity monitoring, CCTV, fraud alerts, reconciliation, vulnerability scanning.
- Corrective: restores service or reduces recurrence after detection/impact. Examples: incident containment, patching the exploited weakness, restoring tested backups, correcting records, rotating credentials, revising procedures.
Other common labels add nuance: directive tells people what to do (policy), deterrent discourages action (warning/signals), and compensating provides an alternative when the preferred control is impractical. These are not substitutes for the preventive/detective/corrective classification when the question explicitly asks for it; classify by primary function and explain overlap.
Control design principles
- Defense in depth: multiple independent layers limit single-point failure.
- Least privilege and separation of duties: give only needed access and split risky actions so one person cannot complete the whole fraud.
- Accountability: unique identities, logs, review, and time synchronization make actions traceable.
- Resilience: backups, redundancy, alternate procedures, and recovery tests protect availability.
- Risk-based tailoring: prioritize high-impact assets and realistic threats; controls have cost, usability, and residual risk.
- Continuous monitoring: a control that is never reviewed may silently fail.
A control can be preventive for one property and detective for another, so explain its mechanism rather than relying on the label alone. NIST CSF 2.0 groups outcomes as Govern, Identify, Protect, Detect, Respond, and Recover; the functions complement, rather than replace, control classification. NIST CSF 2.0
Worked decision scenario: ransomware in a clinic
Preventive: patch systems, restrict privileges, segment clinical devices, use MFA, and train staff to report suspicious messages. Detective: endpoint alerts, centralized logs, unusual-encryption monitoring, and backup-failure alerts. Corrective: isolate infected devices, remove malware, rotate credentials, restore clean tested backups, notify affected parties as required, and patch the root cause. A backup is not automatically protective: offline/immutable copies and restoration tests are needed. The control set should be mapped to availability, confidentiality, integrity, cost, and recovery-time objectives.
Exercise — reveal after committing
Classify: (a) a firewall blocks an unauthorized inbound connection; (b) a SIEM alerts on a mass download; (c) an organization restores a clean database and patches the exploited service.
Revealed answer: (a) preventive; (b) detective; (c) corrective. A firewall may also generate detective logs, and patch management can be preventive for future incidents, but the described primary actions fit the requested classes.
Exam lens
- Preventive ≠ detective: stop/reduce before or during versus discover/alert after or during.
- Corrective ≠ backup only: correction includes containment, recovery, remediation, and preventing recurrence.
- Do not list controls without connecting them to a threat, vulnerability, asset, and CIA impact.
- Mention people, policy, physical, and technical controls; security is not only a firewall.
Rapid revision checklist
- Define security control.
- Give three examples of each primary timing class.
- Explain defense in depth, least privilege, separation of duties, and accountability.
- Map controls to a threat and CIA property.
- Distinguish NIST CSF functions from NIST SP 800-53 control catalog.
Key takeaways
- Controls reduce risk through prevention, detection, and correction.
- Layering matters because every control can fail or be bypassed.
- Corrective work restores operations and fixes the exploited weakness.
- Strong exam answers connect each control to a specific threat and impact.
Sources
- Rainer & Prince, Management Information Systems (Wiley) — textbook exam framing for controls and security safeguards.
- Laudon & Laudon, Management Information Systems: Managing the Digital Firm, 10th ed. — textbook exam framing for controls, access, and continuity.
- Boddy & Boonstra, Managing Information Systems: Strategy and Organization — textbook exam framing.
- NIST, SP 800-53 Rev. 5: Security and Privacy Controls — supplement for a control catalog and tailoring.
- NIST, Cybersecurity Framework 2.0 — supplement for Govern/Identify/Protect/Detect/Respond/Recover.