Overview of Security Controls in IT Security
This video provides a comprehensive guide to security controls, the frameworks used to protect data, systems, buildings, and people from security risks. It covers four broad categories and six specific control types, showing how they work together to prevent, detect, and mitigate attacks. For a foundation on these concepts, see Mastering General Security Concepts for Security Plus Exam 2024.
The Four Categories of Security Controls
Technical Controls
Implemented using technology systems (e.g., operating system policies, firewalls, antivirus software). This approach is closely tied to maintaining data confidentiality and integrity, as discussed in Understanding the CIA Triad: Key Concepts in Computer Security.
Managerial Controls
Policies and procedures that guide behavior (e.g., security documentation, standard operating procedures).
Operational Controls
Human-driven measures (e.g., security guards, lunch-and-learn sessions, awareness posters).
Physical Controls
Tangible barriers limiting physical access (e.g., guard shacks, fences, badge readers, locks). These controls help define and protect Network Security Zones and Attack Surface Reduction.
Six Control Types and Examples
Preventive Controls
Limit access to resources.
- Technical: Firewall rules blocking network traffic
- Managerial: Onboarding policies for new hires
- Operational: Guard shack checking IDs
- Physical: Door locks preventing room access
Deterrent Controls
Discourage attackers without fully preventing access.
- Technical: Splash screen warning unauthorized users
- Managerial: Threat of demotion for data breaches
- Operational: Front reception desk greeting visitors
- Physical: Warning signs about consequences
Detective Controls
Identify and log breaches after they occur. For more on identifying threats, explore Common Cybersecurity Threat Vectors and How to Protect Your Systems.
- Technical: System log collection and review
- Managerial: Regular review of login reports
- Operational: Security patrols checking for break-ins
- Physical: Motion detectors triggering alerts
Corrective Controls
Reverse or minimize damage after an event.
- Technical: Restoring from backup after ransomware
- Managerial: Policies for incident reporting
- Operational: Contacting law enforcement for intrusions
- Physical: Fire extinguishers to stop fires
Compensating Controls
Alternative measures when primary controls aren't feasible.
- Technical: Firewall rule blocking vulnerability exploitation
- Managerial: Separation of duties among staff
- Operational: Multiple guards working simultaneously
- Physical: Generator compensating for power outage
Directive Controls
Weak controls that direct secure behavior.
- Technical: Policy to store sensitive data in encrypted folders
- Managerial: Compliance policies and procedures
- Operational: Security policy training for users
- Physical: Sign saying "Authorized Personnel Only"
Key Takeaways
- Security controls fit a matrix of four categories (technical, managerial, operational, physical) and six types (preventive, deterrent, detective, corrective, compensating, directive)
- Controls evolve with technology and organizational needs
- Using multiple control types across all categories strengthens security posture. For a structured approach to implementing these controls, refer to the Comprehensive Guide to ISO 27001 Implementation, Risk Assessment, and Business Continuity.
If you've spent any amount of time in IT security, you know there are many different security risks
that you need to prepare for. The attackers are looking for different ways to gain access to our systems.
And we need to find different ways to prevent them from getting that access. But of course, we're not just protecting data.
We're also protecting physical systems, buildings, people, and everything in our organization. In this video, we'll look at different security controls
and how they can be used to prevent events from occurring in the first place. We can minimize the impact of events
that ultimately do occur. And in many cases, we can limit the damage if someone does find a way into our computing environment.
Let's look at some very broad categories of security controls. The first category we'll look at are technical controls.
These are controls that we implement using some type of technical system. So if you're someone who is managing an operating system,
you might set up policies and procedures within the operating system that would allow or disallow different functions from occurring.
We can also put firewalls, antivirus, and other types of software into this category of technical controls.
As a security administrator, you'll also want to create a series of policies that explain to people the best way to manage their computers, their data,
or their other systems. We refer to these as managerial controls. So if you are creating a series of policies and procedures
or you're creating an official security policy documentation, you'll often put these managerial controls inside of your security policies.
You might also see these managerial controls implemented into day-to-day processes as part of your standard operating procedures.
Another important control category are the operational controls. Unlike using technology to manage these controls,
operational controls are using people to be able to set these controls. So if you have security guards at your place of work,
you're doing monthly lunch and learns, or you have some type of posters or awareness program at work to help explain the best practices for IT security,
then you can put these into the category of operational controls. And the last category that we have are physical controls.
As the name implies, these are controls that would limit someone's physical access to a building, a room, or a device.
This might be something like a guard shack. So they can check everyone coming into a particular area. Maybe there are fences and locks to keep people out.
Or maybe use badge readers to limit the access into certain areas within your building. So in this video, we'll focus on these four categories
of controls-- the technical, managerial, operational, and physical. And in this video, we'll look at a number of different control
types and determine where we would fit certain control types into certain categories. The first control type we'll look at
is a preventive control type. This is a control type that limits someone access to a particular resource.
You can think of this as something like a firewall rule, which would prevent somebody from gaining access to a particular area
of your network. Or it may be something that's more tangible, such as a guard shack checking everyone's identification
as they come into your facility. A good way to test yourself with these different control types is to determine what category will a certain type fit into.
So when we deal with preventive control types, we can look at firewall rules. And since those are handled at a technical level,
then those would fit into the technical category. As we hire people, we may want to set a certain type of policy for onboarding.
And those would be policies set as part of a managerial category. We've already mentioned a guard shack
checking everyone's identification. And since that's done by a person, we can fit that into an operational category.
And lastly, we have door locks, which are physical devices preventing access to a room. So that would fit into the physical category.
Another important control type is a deterrent. And although a deterrent may not prevent someone from accessing a resource, it may give them a discouragement
or have them think twice about the attack that they're planning. For example, when you start an application,
there may be a splash screen that provides security information and restricts people who are not authorized from gaining access
to that system. Or there might be the threat of a demotion or a dismissal if somebody gains access to data that they should not
be accessing. There might also be a front reception desk greeting everyone who walks in or warning signs telling people
that if they gain access to this facility that there would be consequences. These fit perfectly into our four categories.
A splash screen is a deterrent that fits into the technical category. A demotion is a managerial category.
The reception desk fits into the operational category. And the warning signs are a physical deterrent. A detective control type can identify and, in some cases,
warn us when a particular breach has occurred. This may not prevent access. But it would give us a warning and log information
about that particular attack. An example of a detective control type may be a process of collecting, reviewing,
and going through system logs. Or you may be reviewing log-in reports about who's gained access to your systems.
There might be someone patrolling the property, looking for cases where someone might have broken into your facility.
And you might have motion detectors so that you're automatically notified if something is moving in an area
where normally there should be no motion. The system logs that are detailing everything that's going on in your systems would fit
into the technical category. Someone reviewing log-in reports every day or every week would fit into the managerial category.
Someone patrolling the property would be an operational category. And then the motion detectors provide us
with a physical category. If there is a notification that someone has breached a system or gained access into a certain area of your business,
then you want to apply a corrective security control. A corrective security control is something that occurs after the event has been detected.
This is sometimes able to reverse the impact of that particular event. Or you may be able to continue operating
with your business with minimal downtime, thanks to these corrective controls. For example, if a computer has been infected with ransomware
and it has encrypted everything on that system and made all of the data inaccessible, you can simply erase everything on that computer
and restore it back to a known good system using your backups. You might also want to create policies so that if there are security issues
or something unusual that you see happen, then those would be rolled up into an alert or some type of notification.
And if you find that someone has jumped your fence or they've tried to get in through a door in your building, you may need to contact law enforcement
to be able to correct that particular incident. And if something is caught on fire, you can grab a fire extinguisher and make sure
that that fire doesn't spread any further, thereby correcting that particular event. And as you might expect, those are four events
that certainly fits into the four categories that we have. For example, recovering from a backup would be a technical category.
Being able to have policies for reporting issues when they occur would be in the managerial category. Contacting authorities for some type of legal issue
would be an operational category. And your fire extinguisher is a physical category. You might also find yourself in a situation
where a security event has occurred, but you don't have the resources or means to be able to reverse what that particular event has caused.
In those cases, you may want to use a compensating control type, which provides you with using other means in a way to control that particular security event.
This may be something you use on a temporary basis until you're able to put together a plan to resolve the overall security incident.
For example, you might have an application that is important for your organization. But the application developer has told you
that they've identified a significant security vulnerability in that software. Since the application developer is
going to provide you with a patch sometime in the future, you may want to set some type of firewall rule today that would prevent somebody from exploiting
that particular vulnerability. Or this might be a case where you can separate different duties between different individuals
and limit the scope of any type of security concern. Or you might have multiple security guards all working at the same time to make sure
that no single security guard has complete access to everything in your environment. And if you lose power in your building,
you might want to have a generator so that while you're waiting for main power to be restored, you can compensate by turning on your generator.
Those are our four different categories of a compensating control. We have a technical category of blocking that traffic
instead of patching the application. There may be a separation of duties for the people that work in your organization.
And that fits into the managerial category. You might require multiple security staff working simultaneously.
And that would be the operational category. And lastly, having a power generator to compensate for a power outage fits
into the physical category. The last control type we'll look at is a directive control type. This is a relatively weak security control
because it is one where you are directing someone to do something more secure rather than less secure. For example, you may require everyone
to store sensitive information into a protected and encrypted folder on their system. This requires the user to make a decision
about what data may be sensitive and what data may be nonsensitive. And then they are directed to store the sensitive information
in the protected folder. As part of our security policies, we may want to add compliance policies and procedures so
that everyone understands the proper processes to use for security in your environment. You might also train users on what the proper security
policies might be. And another example of a directive control may be a sign that you put on a door that says
"authorized personnel only." There might not be a lock on the door. But the sign saying "authorized personnel only"
directs people to either enter or not enter that particular door. So to summarize these, our file storage policies
will direct people to this technical category. A compliance policy fits into a managerial category. Someone performing a security policy training course
would be a directive control type fitting into the operational category. And a sign on a door that says "authorized personnel only"
fits into the physical category. The examples I provided for the different security controls and the categories where they fit
are simply one single example. And you can probably think of a number of different examples that you could fit into any of those squares in our matrix.
You could probably also think of different security controls that might fit into a different category of control or a different type of control.
You might also find as our technology changes and our security processes evolve that there might be new control types that we
could fit into our chart. And of course, not everybody uses the same security controls.
So the ones that you use in your organization may be very different than someone else's organization.
The four categories are Technical (technology-based, like firewalls), Managerial (policies and procedures), Operational (human-driven actions, like security guards), and Physical (tangible barriers, like locks). Each category addresses a different layer of protection—technical handles digital threats, managerial guides behavior, operational relies on people, and physical secures physical assets.
Yes! Technical: firewall rules blocking traffic. Managerial: onboarding policies for new hires. Operational: a guard shack checking IDs. Physical: door locks preventing room access. Each works proactively to stop security incidents before they happen.
Preventive controls directly block access (e.g., a lock), while deterrent controls discourage attackers without fully preventing access, like a splash screen warning or warning signs. Deterrents rely on psychology to reduce threats, whereas preventive controls physically or technically stop them.
Detective controls identify breaches after they occur (e.g., system logs or motion detectors), while corrective controls minimize damage and restore operations (e.g., restoring from backup or using fire extinguishers). Together, they enable incident detection and rapid recovery.
Compensating controls act as alternatives when primary controls aren’t feasible due to cost, technical limitations, or operational constraints. For example, using a generator during a power outage or separating duties among staff to prevent fraud when dedicated systems aren’t available.
A directive control guides secure behavior through rules or signs, like a policy to store files in encrypted folders or a sign saying 'Authorized Personnel Only.' It’s weak because it relies on compliance and enforcement rather than physical or technical barriers, making it easy to ignore.
By implementing multiple control types across all four categories—technical, managerial, operational, and physical—organizations create layered defense. For instance, combine firewalls (technical), security policies (managerial), guard patrols (operational), and badge readers (physical) to prevent, detect, and respond to threats effectively.
Keep this summary
Save it to LunaNotes and it becomes a real note in your library — editable, searchable, and ready to turn into flashcards or a diagram. Free to start.
Save to LunaNotesOr summarise for another video.
This summary and transcript were automatically generated using AI with the Free YouTube Transcript Summary Tool by LunaNotes.
Related summaries
Mastering General Security Concepts for Security Plus Exam 2024
Dive into key concepts of security controls, change management, and cryptographic solutions for Security Plus Exam prep.
Common Cybersecurity Threat Vectors and How to Protect Your Systems
This video explores various methods attackers use to infiltrate systems, known as threat vectors, including messaging platforms, malicious files, network vulnerabilities, and supply chain risks. Learn key strategies to identify, prevent, and mitigate these threats to enhance your organization's cybersecurity posture.
Network Security Zones and Attack Surface Reduction
Explore the fundamentals of network security architecture, focusing on security zones and attack surface reduction. Learn how to logically segment networks with zones like trusted and untrusted to control traffic flow and minimize vulnerabilities, while understanding practical steps to protect network connectivity and data.
Security Engineering: Why Bridges Don't Fall but Computers Get Hacked
This lecture explores the concept of "security theater" through the Halifax explosion case study, teaching students to think like attackers rather than defenders. Key topics include physical security vulnerabilities, the economics of zero-day exploits, and why complex systems will always have security flaws.
Understanding Cyber Resilience: Key Strategies for Businesses
In this informative webinar, experts discuss the importance of cyber resilience for businesses, highlighting the need for effective governance, risk management, and the implementation of the Essential Eight strategies. Attendees gain insights into the evolving cyber threat landscape and the role of corporate governance in mitigating risks.
Most viewed summaries
A Comprehensive Guide to Using Stable Diffusion Forge UI
Explore the Stable Diffusion Forge UI, customizable settings, models, and more to enhance your image generation experience.
Kolonyalismo at Imperyalismo: Ang Kasaysayan ng Pagsakop sa Pilipinas
Tuklasin ang kasaysayan ng kolonyalismo at imperyalismo sa Pilipinas sa pamamagitan ni Ferdinand Magellan.
Mastering Inpainting with Stable Diffusion: Fix Mistakes and Enhance Your Images
Learn to fix mistakes and enhance images with Stable Diffusion's inpainting features effectively.
Pamamaraan at Patakarang Kolonyal ng mga Espanyol sa Pilipinas
Tuklasin ang mga pamamaraan at patakaran ng mga Espanyol sa Pilipinas, at ang epekto nito sa mga Pilipino.
How to Install and Configure Forge: A New Stable Diffusion Web UI
Learn to install and configure the new Forge web UI for Stable Diffusion, with tips on models and settings.
Found this summary useful?
Take it with you. One click puts it in your own LunaNotes library.
Save to LunaNotes