Applicable Types of Controls and Control Categories
Effective risk management involves applying technical, physical, and administrative controls, including directive, deterrent, preventive, and compensating measures tailored to specific threats.
7 slides · 4 min read · Domain 1
Security controls can be arranged • Technical/logical controls. Controls implemented with or by automated or according to many criteria. One electronic systems. Examples include way to consider controls is how the firewalls, electronic badge readers, and controls are implemented, meaning access control lists. Many IT systems the type of control:
include some kind of technical control capacity or functionality; for instance, routers can be set to reject traffic that may be indicative of possible attacks.
- Physical controls. Controls implemented through a tangible mechanism. Examples include walls, fences, guards, and locks. In modern organizations, many physical control systems are linked to technical/ logical systems, such as badge readers connected to door locks.
- Administrative controls. Controls implemented through policy and procedure. Examples include access control processes and requiring multiple personnel to conduct a specific operation. Administrative controls in modern environments are often enforced in conjunction with physical or technical controls, or both, such as an accessgranting policy for new users that requires login and approval by the hiring manager.
Security Control Categories
- Directive (administrative). Controls that
Another way to group security impose mandates or requirements. These controls is by how they take effect.
can include policies, standards, signage, or
In the security industry, controls notification, and they are often combined are typically arranged into these with training.
categories:
- Deterrent. Controls that reduce the likelihood that someone will choose to perform a certain activity. These can include notification, signage, cameras, and the noticeable presence of other controls.
- Preventive. Controls that prohibit a certain activity. These can include walls and fences; they prohibit people from entering an area in an unauthorized manner.
- Compensating. Controls that mitigate the effects or risks of the loss of primary controls. Examples include physical locks that still function if an electronic access control system loses power, or personnel trained to use fire extinguishers or hoses in the event that a sprinkler system does not activate.
- Detective. Controls that recognize hostile or anomalous activity. These can include motion sensors, guards, dogs, and intrusion detection systems.
- Corrective. Controls that react to a situation to perform remediation or restoration. Examples include fire suppression systems, intrusion prevention systems, and incident response teams.
- Recovery. Controls designed to restore operations to a known good condition following a security incident. These can include backups and disaster recovery plans.
This form of categorization is not
- Surveillance cameras are a deterrent control just the presence of them
absolute or distinct; many controls discourages someone from entering a can fall into several categories, surveilled area, for fear of being observed).
depending on their implementation and operation. For instance:
- Detective control is combined with live monitoring by guards or a motion-sensing capability.
- Compensating controls provide additional detection capability that augments gate guards or other controls. Controls of other various types (administrative, technical, and physical) can be used in each of these categories.
Type of Control
Physical Fences Locks Badge rystem Security guard Biomatric system Mantrap doors Lighting Motion detectors Closed circuit TVs Offsite focility Preventive Avoid undesirable events from occurring
Security policy Monitoring and supervising Separation of duties Job rotation Information classification Personnel procedures Investigations Testing Security-awareness training Techrical AOLs Rovers Encryptice Aude legs IDS Antivirus software Senerinages Smart cards Dial-up call-back systems Data backup i
Detective Corrective
Deterrent Recovery
Idensify undesirable events that
Discourage security Correct undesirable Restore resources have occurred events that have occurred violations and capabilities Compensation Provide Alternatives to other controls
- XXX
Figure: How specific control types fall into different categories
When selecting and implementing security controls, it is always preferable to use multiple types and to implement them among the various categories rather than to rely on one type or category; this is called defense in depth (DiD or layered defense), where controls of various types and kinds overlap each other in coverage.
There are two reasons to implement DiD. Firstly, relying on a single control type or category increases the possibility that a single control failure could lead to enhanced risk. For instance, if the organization were to rely solely on technical controls and power were interrupted, those controls would not function properly. Moreover, a new vulnerability might be discovered in a specific control; if that was the sole control an organization relied on, the organization would become completely exposed. Secondly, using multiple types and categories of controls forces an aggressor to prepare multiple means of attack instead of just one. By making the task of the attacker more complicated, we reduce the number of possible attackers (many people know one thing well, but few people know many things well). For instance, combining strong technical and physical controls could require the aggressor to have both hacking and physical intrusion toolkits, which increases the price of the attack for attacker, thereby reducing the number of potential attackers.
