0% found this document useful (0 votes)
16 views4 pages

Understanding Security Controls in IT

Uploaded by

kayebright120
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views4 pages

Understanding Security Controls in IT

Uploaded by

kayebright120
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

INTRODUCTION TO INFORMATION SECURITY

Module 7 – Security Controls

Learning Objectives
After completing this module, you are expected to:
▪ know what security controls are
▪ learn the types and functions of security controls
▪ understand examples of security control frameworks and best practices

7.1 What are Security Controls?

Security controls are parameters implemented to protect assets important to an organization.


They include any type of policy, procedure, technique, method, solution, plan, action,
countermeasure, or device designed to help reduce or mitigate the risk to those assets.
Recognizable examples include surveillance systems, firewalls, and antivirus software.

Security controls are not randomly or arbitrarily chosen. Generally, they flow out of the
organization’s risk management process, beginning with defining the overall IT security strategy
and goals, and followed by defining specific control objectives, i.e., statements about how the
organization plans to effectively manage risk. Once the organization defines control objectives,
it can assess the risk to individual assets and then choose the most appropriate security
controls to put in place.

One of the most straightforward models for classifying controls is by TYPE: physical, technical,
or administrative, and by FUNCTION: preventative, detective, and corrective.1

1
[Link]
7.2 Security Control Types

Physical controls describe anything tangible that is used to prevent or detect unauthorized
access to physical areas, systems, or assets. This includes things like fences, gates, guards,
security badges and access cards, biometric access controls, security lighting, CCTVs,
surveillance cameras, motion sensors, fire suppression, as well as environmental controls like
HVAC and humidity controls.

Technical controls (also known as logical controls) include hardware or software mechanisms
used to protect assets. Some common examples are authentication solutions, firewalls, antivirus
software, intrusion detection systems (IDSs), intrusion protection systems (IPSs), constrained
interfaces, as well as access control lists (ACLs) and encryption measures.

Administrative controls refer to policies, procedures, or guidelines that define personnel or


business practices in accordance with the organization's security goals. These can apply to
employee hiring and termination, equipment and Internet usage, physical access to facilities,
separation of duties, data classification, and auditing. Security awareness training for
employees also falls under administrative controls.

7.3 Security Control Functions

Preventative controls describe any security measure that’s designed to stop unwanted or
unauthorized activity from occurring. Examples include physical controls such as fences, locks,
and alarm systems; technical controls such as antivirus software, firewalls, and IPSs; and
administrative controls like separation of duties, data classification, and auditing.

Detective controls describe any security measure taken or solution that’s implemented to
detect and alert to unwanted or unauthorized activity in progress or after it has occurred.
Physical examples include alarms or notifications from physical sensor (door alarms, fire
alarms) that alert guards, police, or system administrators. Honeypots and IDSs are examples
of technical detective controls.

Corrective controls include any measures taken to repair damage or restore resources and
capabilities to their prior state following an unauthorized or unwanted activity. Examples of
technical corrective controls include patching a system, quarantining a virus, terminating a
process, or rebooting a system. Putting an incident response plan into action is an example of
an administrative corrective control.

7.4 Security Control Frameworks

Systems of security controls, including the processes and documentation defining


implementation and ongoing management of these controls, are referred to as frameworks or
standards.

Frameworks enable an organization to consistently manage security controls across different


types of assets according to a generally accepted and tested methodology.

National Institute of Standards and Technology Cyber Security Framework

The National Institute of Standards and Technology (NIST) created a voluntary framework in
2014 to provide organizations with guidance on how to prevent, detect, and respond to
cyberattacks. The assessment methods and procedures are used to determine if an
organization’s security controls are implemented correctly, operate as intended, and produce
the desired outcome (meeting the security requirements of the organization). The NIST
framework is consistently updated to keep pace with cybersecurity advances.2

Center for Internet Security Controls

The Center for Internet Security (CIS) developed a list of high-priority defensive actions that
provide a “must-do, do-first” starting point for every enterprise looking to prevent cyberattacks.

According to the SANS Institute, which developed the CIS controls, “CIS controls are effective
because they are derived from the most common attack patterns highlighted in the leading
threat reports and vetted across a very broad community of government and industry
practitioners.”3

2
Source: [Link]
3
Source: [Link]
7.5 Security Control Best Practices

A well-developed framework ensures that an organization does the following:


• Enforces IT security policies through security controls
• Educates employees and users about security guidelines
• Meets industry and compliance regulations
• Achieves operational efficiency across security controls
• Continually assesses risks and addresses them through security controls

A security solution is only as strong as its weakest link. The organization should consider
multiple layers of security controls (which is also known as a defense-in-depth strategy) to
implement security controls across identity and access management, data, applications,
network or server infrastructure, physical security, and security intelligence.4

4
Source: [Link]

Common questions

Powered by AI

Corrective security controls differ from preventive controls in their timing and purpose. Preventive controls are proactive measures aimed at stopping unauthorized activities before they occur; they include locks, antivirus software, and firewalls, among others . In contrast, corrective controls are reactive and applied after a security incident has occurred to repair damage and restore normal operations. Examples include system patching, virus quarantine, and rebooting of a system . While preventive controls aim to avert incidents, corrective controls aim to address them post-occurrence to mitigate impact .

Security controls function in three primary ways: preventative, detective, and corrective. Preventative controls are designed to stop unwanted or unauthorized activities and include examples like fences, locks, antivirus software, and separation of duties . Detective controls aim to detect and alert on such activities; they include alarms and intrusion detection systems (IDSs). Corrective controls are measures taken to repair damage or restore resources and capabilities following an unauthorized activity, such as patching a system or implementing an incident response plan . These functions are supported by types like physical controls (e.g., locks, guards), technical controls (e.g., firewalls, IDSs), and administrative controls (e.g., policies and training).

A well-developed security control framework offers key benefits like enforcing IT security policies, meeting compliance regulations, improving operational efficiency, and enabling continuous risk assessment and mitigation . By providing a structured approach to the application and management of controls, it helps organizations systematically address potential vulnerabilities and align with industry best practices, such as defense-in-depth strategies which recommend multiple security layers to protect assets comprehensively . Additionally, these frameworks guide the consistent implementation and update of security measures aligned with evolving threats, ensuring the organization's resilience against cyber-attacks .

A defense-in-depth strategy enhances the effectiveness of security controls by applying multiple layers of security measures across various domains, such as identity and access management, data security, application, and network infrastructure . This approach ensures that if one control fails, others provide additional protection and time to respond to threats. It addresses different types of threats across multiple vectors and reduces the risk of a single point of failure, aligning with the best practices of enforcing IT security policies and maintaining operational efficiency in security management .

Frameworks like NIST and CIS help organizations manage cybersecurity by providing guidelines and best practices to prevent, detect, and respond to cyber threats. The NIST framework, created to guide organizations in maneuvering through cyberattacks, ensures that security controls are implemented correctly and meet security requirements . Similarly, CIS provides a prioritized list of control actions, which derive from common attack patterns and are vetted by a wide range of practitioners from industry and government to ensure effectiveness . These frameworks offer a structured method to consistently manage security across different assets and align with industry standards .

Technical controls, also known as logical controls, are hardware or software mechanisms such as firewalls, IDSs, and encryption measures used to protect organizational assets . On the other hand, administrative controls encompass policies and procedures like security awareness training and guidelines on data classification, which define personnel practices aligned with security goals . The importance of implementing both lies in their complementary roles; technical controls directly shield systems from attacks, while administrative controls guide human interactions with these systems, promoting a comprehensive, layered security strategy essential for deterring multifaceted threats .

Security control frameworks are necessary for maintaining cybersecurity compliance and operational efficiency as they provide a structured methodology for organizations to implement and manage security controls consistently. Frameworks like NIST help verify that controls are applied effectively to prevent, detect, and respond to security incidents, thereby meeting industry standards and compliance regulations . These frameworks also aid in achieving operational efficiency by streamlining security processes, ensuring risks are continuously assessed and addressed, and enforcing guidelines that minimize the likelihood of overlooked vulnerabilities .

Security awareness training is a vital component of administrative security controls, aiming to educate employees about the organization’s security policies and potential threats. It contributes to the organization’s overall security posture by empowering staff with the knowledge to recognize, report, and mitigate security incidents, therefore reducing human error-related vulnerabilities . By fostering a culture of security-minded behavior, awareness training helps ensure personnel actions complement other security measures, reinforcing a defense-in-depth strategy across all layers of security .

Detective controls facilitate the identification and containment of security breaches by monitoring systems and environments for signs of suspicious activity and anomalies. They are implemented using various methods, such as intrusion detection systems (IDSs) and honeypots to highlight abnormal behavior or unauthorized access attempts in real time . These controls alert security teams to the presence of threats, allowing for timely containment actions like isolating affected systems and initiating incident response protocols, thereby minimizing potential damage and aiding in forensic investigations .

Examples of physical security controls include fences, gates, security badges, access cards, biometric access controls, surveillance cameras, and motion sensors . These controls function to safeguard an organization's assets by restricting unauthorized physical access to critical areas and resources. Elements like CCTVs and surveillance cameras monitor and record activities for real-time vigilance and post-incident analysis, while measures such as guards and biometric access ensure only authorized personnel gain entry, thus deterring potential security breaches .

You might also like