Security controls are *safeguards designed to reduce specific security risks*. So they are used alongside [[Security Frameworks|frameworks]] to ensure that security goals and processes are implemented correctly and that organisations meet regulatory compliance requirements. For example, a control that can be used alongside frameworks to ensure a hospital remains compliant with HIPAA is requiring that patients use multi-factor authentication (MFA) to access their medical records. Using a measure like MFA to validate someone’s identity is one way to help mitigate potential risks and threats to private data. There are three main categories of controls: - [[Managerial controls]] - [[Technical controls]] - [[Operational controls]] - [[Physical controls]] ### Control types Control types include, but are not limited to: - *Preventative* - intend to stop a security issue before it occurs. Firewalls and encryption are examples of preventive controls. - *Corrective* - remediate security issues that have already occurred. Restoring backups after a ransomware attack is an example of a corrective control. - *Detective* - identify security events that have already occurred. Intrusion detection systems are detective controls. - *Deterrent* - seek to prevent an attacker from attempting to violate security policies. Vicious guard dogs and barbed wire fences are examples of deterrent controls. - *Compensating* - controls designed to mitigate the risk associated with exceptions made to a security policy. ^comp - *Directive* - inform employees and others what they should do to achieve security objectives. Policies and procedures are examples of directive controls These controls work together to provide defence in depth and protect assets. ![[Security Controls.jpeg]]