Overview

3 Understanding Security Controls

Security controls are the safeguards organizations use to reduce risk to acceptable levels while enabling business success. The chapter emphasizes selecting controls that fit the nature and value of each asset, considering vulnerabilities and likelihood of threats, and balancing expected risk reduction against cost and operational impact. Effective programs favor maintainable, centralized solutions that raise the attacker’s cost, protect multiple assets when possible, and minimize human intervention—aligning security measures with real business needs and outcomes.

Controls are grouped by how they work—physical (e.g., locks, cameras, mantraps), technical (e.g., firewalls, encryption, IDS/IPS, antimalware), and administrative (e.g., policies, procedures, training, background checks)—and strong security layers all three. They are also classified by purpose: preventive (stop incidents), detective (identify events), corrective (restore and limit damage), deterrent (discourage attempts), directive (guide behavior), and compensating (alternative measures when primaries are not feasible). A single control may serve multiple functions, and while naming conventions vary across frameworks, understanding these categories and types—and how they intersect—is essential.

Defense-in-depth ties these ideas together by layering complementary controls across the organization: from policies, procedures, and awareness; to physical protections; to perimeter defenses; and down to internal networks and individual hosts. This layered, mutually reinforcing approach ensures that if one safeguard fails, others can prevent, detect, or respond to the incident, building resilience. Mastering how to choose, combine, and maintain controls creates a practical, cost-effective security posture that translates directly to both exam readiness and real-world practice.

Illustration of the categories of security controls with examples
Illustration of the defense-in-depth model

Answers to Review Questions

  1. The correct answer is A. Requiring authorization before accessing privileged tools is an example of an administrative control, specifically an instance of segregation of duties (SoD), which refers to the division of roles and responsibilities among different people to reduce the risk of potential errors or fraud. The remaining examples are physical controls, not administrative controls.
  2. The correct answer is A. An Intrusion detection system (IDS) is a type of technical security control. Bollards, fences and turnstiles control access to physical facilities, and thus are types of physical security controls.
  3. The correct answer is B. Security awareness training is an administrative control because it involves educating employees and users about security policies, procedures, and best practices; administrative controls focus on shaping individuals' behaviors and practices to improve overall security.
  4. The correct answer is A. Detective controls alert us to security problems by constantly monitoring activity and recording information, so as to take immediate action in the event of a security control failure. Therefore, a movement sensor is considered a detective control, and is complementary to physical controls.
  5. The correct answer is A. Preventive controls are security measures that are implemented to deter cyber-attacks by preventing potential threats and reducing vulnerabilities that cyber attackers could exploit.

FAQ

What is a security control (safeguard) and why is it used?A security control is a countermeasure applied to protect the confidentiality, integrity, and availability of information and to meet defined security requirements. Organizations use controls to reduce risk to an acceptable level and support business success.
How do you decide which security controls to apply to a specific asset?Select controls based on the asset’s nature, value, vulnerabilities, and the likelihood of threats. For example, corporate laptops benefit from strong passwords, while a public website needs a firewall. The goal is to match controls to the risks and characteristics of each asset.
How should cost-benefit and operational impact influence control selection?Controls should pass a cost-benefit assessment: the expected risk reduction must justify the cost and complexity. Favor controls that raise attacker cost, can protect multiple assets, require minimal human intervention, and are easy to maintain—such as centralized solutions that reduce updates and manual checks.
What are the three categories of security controls and what are examples of each?- Physical: fences, locks, cameras (CCTV), mantraps, turnstiles, bollards, lighting, alarms, badge readers.
- Technical: firewalls, IDS/IPS, encryption, DLP, file integrity monitoring, antimalware.
- Administrative: policies, procedures, standards, security awareness training, background checks, warning signs.
How do NIST’s control categories differ from those used for the exam?NIST categorizes controls as management, operational, and technical. This chapter and the exam emphasize physical, technical, and administrative categories. There’s direct correlation for technical controls, but not a one-to-one mapping for the others—focus on the chapter’s categories for the exam.
What are physical controls and what is CPTED?Physical controls are tangible measures that prevent or restrict physical access to people, facilities, and assets (for example, locks or fences). Crime Prevention Through Environmental Design (CPTED) enhances security by shaping the built environment—such as clear sight lines and good lighting to promote natural surveillance.
What are technical controls, and can a technology be both physical and technical?Technical (logical) controls are hardware and software mechanisms that secure systems, networks, and data—such as firewalls, IDS/IPS, encryption, DLP, FIM, and antimalware. Some technologies can serve as either physical or technical controls; for example, facial recognition can control building entry (physical) or computer login (technical).
What are administrative controls and why is leadership support important?Administrative controls are people- and process-focused directives like policies, procedures, standards, training, and background checks. Senior management backing is essential to embed these practices in daily operations, shape user behavior, and reduce errors (for example, enforcing a strong password policy).
What are the main types of security controls by function, and can one control serve multiple types?- Preventive: stop incidents before they occur (locks, firewalls, IPS, encryption, training).
- Detective: identify incidents after they happen (CCTV recordings, motion sensors, audits, IDS).
- Corrective: limit damage and restore normal operations (backups/restores, antimalware quarantine, updated training).
- Deterrent: discourage violations (warning banners, cameras, guards, fences).
- Directive: guide behavior (SOPs, guard instructions, supervision).
- Compensating: alternate measures when primary controls aren’t feasible (isolated network segments, stricter monitoring). A single control can have multiple functions—for example, a firewall can both prevent access and log attempts.
What is defense-in-depth and how do layered controls work together?Defense-in-depth is a strategy that layers multiple controls across the organization so if one fails, others prevent, detect, or respond to threats. Outer layers include policies, procedures, and awareness; then physical controls; then perimeter defenses (firewalls, VPNs); then internal network and host protections (patching, encryption, IDS). Together they create resilient, overlapping safeguards.

pro $24.99 per month

  • access to all Manning books, MEAPs, liveVideos, liveProjects, and audiobooks!
  • choose one free eBook per month to keep
  • exclusive 50% discount on all purchases
  • renews monthly, pause or cancel renewal anytime

lite $19.99 per month

  • access to all Manning books, including MEAPs!

team

5, 10 or 20 seats+ for your team - learn more


choose your plan

team

monthly
annual
$49.99
$499.99
only $41.67 per month
  • five seats for your team
  • access to all Manning books, MEAPs, liveVideos, liveProjects, and audiobooks!
  • choose another free product every time you renew
  • choose twelve free products per year
  • exclusive 50% discount on all purchases
  • renews monthly, pause or cancel renewal anytime
  • renews annually, pause or cancel renewal anytime
  • Become ISC2 Certified in Cybersecurity ebook for free
choose your plan

team

monthly
annual
$49.99
$499.99
only $41.67 per month
  • five seats for your team
  • access to all Manning books, MEAPs, liveVideos, liveProjects, and audiobooks!
  • choose another free product every time you renew
  • choose twelve free products per year
  • exclusive 50% discount on all purchases
  • renews monthly, pause or cancel renewal anytime
  • renews annually, pause or cancel renewal anytime
  • Become ISC2 Certified in Cybersecurity ebook for free