Control categories
Before we jump right into the control types, I think it is important to learn a bit about what constitutes a control. A control is a measure that helps reduce risk and improve the security posture of the organization. This control can be technical, such as antivirus software, something physical, such as a turnstile, or a policy document that dictates the ideal course in business operations.
These controls can be categorized as follows:
- Preventive (also known as preventative): These controls prevent any security violations and practices. Installing antivirus software to prevent malicious software or a firewall from blocking unknown traffic is an example of preventive control.
- Detective: These controls detect violations of security policies and practices. Intrusion detection systems (IDSs) or audit logs are examples of detective control.
- Corrective: These controls correct a certain issue that has not been prevented or detected and led to an undesired...