§ 3.3Module 3

Security Controls

On this page

3.3 Security Controls

Suggested retrieval lesson: 20–30 minutes.

Recall first

  1. What is the difference between preventive, detective, and corrective controls?
  2. Classify MFA, an alert for impossible travel, and restoring a backup.
  3. Why do organizations use layered controls instead of one perfect control?

Commit before reading.

What a control does

A security control is a safeguard or countermeasure that reduces security/privacy risk by preventing, detecting, correcting, deterring, or directing behavior. Controls can be administrative/managerial, technical/logical, or physical. NIST SP 800-53 presents a flexible catalog of security and privacy controls to be selected and tailored according to organizational risk; it is a supplement, while textbook lists and classifications may use different labels. NIST SP 800-53 Rev. 5

The exam-critical timing classification

Other common labels add nuance: directive tells people what to do (policy), deterrent discourages action (warning/signals), and compensating provides an alternative when the preferred control is impractical. These are not substitutes for the preventive/detective/corrective classification when the question explicitly asks for it; classify by primary function and explain overlap.

Control design principles

A control can be preventive for one property and detective for another, so explain its mechanism rather than relying on the label alone. NIST CSF 2.0 groups outcomes as Govern, Identify, Protect, Detect, Respond, and Recover; the functions complement, rather than replace, control classification. NIST CSF 2.0

Worked decision scenario: ransomware in a clinic

Preventive: patch systems, restrict privileges, segment clinical devices, use MFA, and train staff to report suspicious messages. Detective: endpoint alerts, centralized logs, unusual-encryption monitoring, and backup-failure alerts. Corrective: isolate infected devices, remove malware, rotate credentials, restore clean tested backups, notify affected parties as required, and patch the root cause. A backup is not automatically protective: offline/immutable copies and restoration tests are needed. The control set should be mapped to availability, confidentiality, integrity, cost, and recovery-time objectives.

Exercise — reveal after committing

Classify: (a) a firewall blocks an unauthorized inbound connection; (b) a SIEM alerts on a mass download; (c) an organization restores a clean database and patches the exploited service.

Revealed answer: (a) preventive; (b) detective; (c) corrective. A firewall may also generate detective logs, and patch management can be preventive for future incidents, but the described primary actions fit the requested classes.

Exam lens

Rapid revision checklist

Key takeaways

  1. Controls reduce risk through prevention, detection, and correction.
  2. Layering matters because every control can fail or be bypassed.
  3. Corrective work restores operations and fixes the exploited weakness.
  4. Strong exam answers connect each control to a specific threat and impact.

Sources