Security controls or security measures are safeguards or countermeasures to avoid, detect, counteract, or minimize security risks to physical property, information, computer systems, or other assets. In the field of information security, such controls protect the confidentiality, integrity and availability of information. Systems of controls can be referred to as frameworks or standards. Frameworks can enable an organization to manage security controls across different types of assets with consistency. Security controls reduce the likelihood of any impacts of security incidents and protect the CIA triad for systems and data. While protecting it helps organizations meet their responsibilities, consistent risk management of systems, assets, data, networks and physical infrastructures.
Types of security controls Security controls can be classified by various criteria. One approach is to classify controls by how/when/where they act relative to a security breach, sometimes termed as control types:
Preventive controls are intended to prevent an incident from occurring e.g. by locking out unauthorized intruders; Sometimes known as firewalls or locked server rooms that restrict physical entry Detective controls are intended to identify, characterize, and log an incident e.g. isolating suspicious behavior from a malicious actor on a network or using network monitoring tolls to flag suspicious activity.; Compensating controls mitigate ongoing damages of an active incident, e.g. shutting down a system upon detecting malware After the event, corrective controls are intended to restore damage caused by the incident e.g. by recovering the organization to normal working status as efficiently as possible. Security controls can also be classified according to the implementation of the control (sometimes termed control categories), for example:
Physical controls - includes tangible items such as fences, doors, locks, CCTV systems and fire extinguishers; Procedural or administrative controls - e.g. incident response processes, management oversight, security awareness and training. Technical or logical controls - e.g. user authentication (login) and logical access controls, antivirus software, firewalls; Legal and regulatory or compliance controls - includes privacy laws, policies, regulations and clauses that help organizations handle and protect (e.g. HIPAA, GDPR). These classifications help organizations build a well-designed, multi-layered defense strategy, ensuring layers help control and prevent threats when they are being taking place.
Control effectiveness and lifecycle Security controls include both technical controls (such as access management and firewalls) and administrative controls (including policies and procedures). An effective controls testing and verification process allows:
Identifying safeguards that are protecting confidentiality, integrity, and availability of assets. Detailed overview of any security posture of the service. Contribution to any mitigation plans that may be prioritized for reducing risks arising because of any weaknesses or failures of controls Steps for assessment: Document security control implementation: securing infrastructure, configuring components, identifying & access management, security polices Monitor & verify security controls: Usually manual or automated testing and it tests penetration, reviewing logs, vulnerability scanning, any surveys and interviews with staff, and more. Reporting test results: Generating reports, metrics, trends Controls are part of a risk treatment strategy applied after risk assessment and designing, building, operating, and changing them is a part of the lifecycle.
Purpose in organizations University IT policy states that “Using a set of standardized controls allows IT security to ensure all University and Medical Center areas are protected from threats.” Controls in four basic categories: Computer Controls, Data Protection, Network Protections, User Authentication Computer Controls: Organizations may implement email protection, endpoint detection & response, centralized patch management, and domain membership. Data Protection: For protecting data organizations may equip full disk encryption and media destruction Network Protection: Protecting the network is important for keeping information safe from unwanted users. Organizations may use flow monitoring, logging network & system activity, network border protections and prohibit firewall to be bypassed to reduce an attack. User Authentication: Organizations may use two-factor authentication, may force users to change their passwords annually, have only authorized account management, and use a Local Admin Password Solution (LAPS).
Information security standards and control frameworks
The ISO/IEC 27000 series standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. The most recent version, ISO/IEC 27001;2022, released in October 2022, specifies 93 controls; some of the most well-known standards are outlined below.
International Standards Organization
ISO/IEC 27001:2022 was released in October 2022. All organizations certified to ISO 27001:2013 are obliged to transition to the new version of the Standard within 3 years (by October 2025). The 2022 version of the Standard specifies 93 controls in 4 groups:
A.5: Organisational controls A.6: People controls A.7: Physical controls A.8: Technological controls It groups these controls into operational capabilities as follows:
The previous version of the Standard, ISO/IEC 27001, specified 114 controls in 14 groups:
A.5: Information security policies A.6: How information security is organised A.7: Human resources security - controls that are applied before, during, or after employment. A.8: Asset management A.9: Access controls and managing user access A.10: Cryptographic technology A.11: Physical security of the organisation's sites and equipment A.12: Operational security A.13: Secure communications and data transfer A.14: Secure acquisition, development, and support of information systems A.15: Security for suppliers and third parties A.16: Incident management A.17: Business continuity/disaster recovery (to the extent that it affects information security) A.18: Compliance - with internal requirements, such as policies, and with external requirements, such as laws.
… excerpt ends here. Continue reading the full article.
