← Back to list

Security Controls

Most of the readers here will be familiar with Ocean’s Eleven (2001) which features Danny Ocean (George Clooney) and his team robbing three…

Nidhi S · 2026-02-03 16:40 · 0 claps · 3.5 min read
#cybersecurity #cybersecurityfundamentals #cybersecurity-basics #security-control
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

Security Controls

Most of the readers here will be familiar with Ocean’s Eleven (2001) which features Danny Ocean (George Clooney) and his team robbing three Las Vegas casinos simultaneously. They bypass guards, sophisticated electronic security systems, and coded locks.

These security levels like the guards, electronic security system and coded locks are what we would call the security controls in cybersecurity terms, if they protect digital assets.

Security Controls are the techniques, technologies and policies that organisations can implement, to safeguard their information systems and data from any harm / destruction / theft.

Just like one level of security is not sufficient to protect any physical asset, the digital systems also need to be protected through multiple layers of security. This layered approach to security is called Defence in Depth. It involves securing digital assets in a layered manner just like a castle with multiple levels of security — the big walls, moats, the watchtowers, soldiers with weapons, animals trained for warfare etc.

If organisations need to defend themselves against the threat actors — they need security controls.

Security Controls Categories (Based on their Nature):

  1. Physical Controls
  2. Managerial Controls
  3. Operational Controls
  4. Technical Controls

Physical Controls

Tangible and real world layer where security measures are implemented in non digital manner. These can be security guards, security gates, fire extinguishers, CCTV cameras installation etc. These ensure that physical safety is ensured at all times to critical infrastructure.

Managerial / Administrative Controls

Administrative Controls work at the strategic layer and ensure that security strategy & governance policies are aligned with the business goals and risk posture of the organisation. Risk assessment, management and Incident response strategies are developed at this layer.

Operational Controls

Operational Controls work at the level of process and procedures, and require human actions to govern them. For example, password policy, employee training, back up, account reviews etc. These govern security related processes and procedures used in day to day activities to ensure security in those operations.

Technical Controls

Technical controls work at the technology layer. They encompass the technologies, hardware, software solutions which are implemented to reduce risk. The examples include the Firewall, Encryption, IDS and IPS etc. They work at software or hardware level and can be automated.

In context of a residential buildings — the doors, the security guards and are the physical controls, the CCTV recording is the Technical Control, using visitor entry passes is an Operational control and the decisions regarding security and the budget allocation towards it comes under Administrative control.

Security Controls Types (Based on their Purpose):

  1. Preventative Controls
  2. Deterrent Controls
  3. Detective Controls
  4. Corrective Controls
  5. Compensating Controls
  6. Directive Controls

Preventative Controls

Preventative controls are meant to proactively identify and prevent threats from penetrating the organisation’s information systems. For example firewalls are preventative controls because they can detect harmful traffic and block it from entering the system.

Deterrent Controls

Deterrent controls are controls that discourage potential attackers from trying to attack. The aim is to make it seem less appealing or more costly for the threat actors to attempt an attack. For example the warning sign in the lift saying, “you are being watched!” — this warning sign is a deterrent control and not actual CCTV. Warning signs can also be attached to the website or corridors of the company.

Detective Controls

Detective controls are controls that monitor and report malicious activities occurring in the systems. The goal of these controls are detection and notification. Examples could be CCTV cameras can help detect and notify regarding threats but they cannot stop them, Intrusion Detection Systems(IDS) scan network traffic for suspicious packets and notify system administrators

Corrective Controls

Corrective controls help mitigate the impact of an attack. For example if a malware is detected, the antivirus system quarantines it. The antivirus software, by quarantining this malware, is acting as a corrective control mechanism. So when detecting the virus, the antivirus software is acting as detective control but when quarantining it / removing it — it takes the role of the corrective control.

Compensating Controls

Compensating controls are meant to be used as a substitute / alternative to the primary control when the primary security controls are not feasible or impossible to implement due to technical reasons. These ensure protection is intact even if the primary control is not available. They are mostly implemented when certain systems cannot be protected due to version issues or incompatible due to legacy systems.

Directive Controls

These controls lay security standards for an organisation by setting policies and documentation related to the dealing with information systems. These are guidelines that determine how the company assets and resources can be used by employees or contractors or even the third parties. Example Acceptable Use Policy (AUP).

Security controls are not about deploying a single tool or policy and assuming everything is secure. Just like in the real world, protecting digital assets requires multiple layers working together — people, processes, and technology.

No organisation is immune to cyber threats, but a well-designed combination of preventive, detective, and corrective controls can significantly reduce risk and limit the impact of an attack. Understanding the different types and purposes of security controls helps organisations make informed decisions rather than relying on ad-hoc or reactive security measures.


메타데이터
post_id
4beebbd18d1e
slug
security-controls-4beebbd18d1e
url
https://medium.com/@nidhisharma.freelancework/security-controls-4beebbd18d1e
canonical_url
https://medium.com/@nidhisharma.freelancework/security-controls-4beebbd18d1e
author_url
https://medium.com/@nidhisharma.freelancework
status
ok
fetched_at
2026-08-08 22:49:35