Classify controls by implementation and function, then combine preventive, detective, and recovery outcomes without assuming one safeguard is enough.
What you will be able to do
- Distinguish administrative controls from technical controls in a realistic security control types and functions case.
- Interpret the evidence and boundary associated with physical controls.
- Choose an appropriate action involving detective function without exceeding the stated authority.
- Verify corrective and recovery through an observable result and a documented handoff.
01
Frame Security Control Types and Functions
Classify controls by implementation and function, then combine preventive, detective, and recovery outcomes without assuming one safeguard is enough.
A small office protects a network closet and its administrator accounts. The team must distinguish governance work, technical enforcement, physical evidence, detection, and restoration.
Keep observed facts, working assumptions, authorized actions, safety boundaries, and expected evidence separate. Begin with read-only inspection and preserve the context another analyst needs to reproduce the decision.
02
Administrative Controls
Administrative controls use policy, planning, training, approval, and review to shape behavior. Within security control types and functions, this concept answers a separate question and should retain its own evidence.
Assign accountable roles and preserve evidence that required decisions occurred. Apply that action to the named case before expanding the investigation or changing protected state.
Respect this boundary: do not assume a written rule changes behavior without implementation. The required result is specific: the workflow shows ownership, approval, and review evidence.
03
Technical Controls
Technical controls use system mechanisms to enforce, detect, or protect an outcome. Within security control types and functions, this concept answers a separate question and should retain its own evidence.
Configure the mechanism against a stated requirement and test both allow and deny paths. Apply that action to the named case before expanding the investigation or changing protected state.
Respect this boundary: do not measure effectiveness only by installation status. The required result is specific: the mechanism produces the intended result on the real path.
04
Physical Controls
Physical controls protect facilities, equipment, media, and environmental conditions. Within security control types and functions, this concept answers a separate question and should retain its own evidence.
Match barriers, monitoring, and response to the asset and plausible entry path. Apply that action to the named case before expanding the investigation or changing protected state.
Respect this boundary: do not treat a locked door as proof that access is reviewed. The required result is specific: entry records and inspection confirm the boundary operates.
05
Detective Function
A detective control reveals activity or state that requires interpretation and response. Within security control types and functions, this concept answers a separate question and should retain its own evidence.
Define the signal, expected context, owner, severity, and investigation path. Apply that action to the named case before expanding the investigation or changing protected state.
Respect this boundary: do not treat an alert as proof of compromise. The required result is specific: a controlled event produces a useful and routed signal.
06
Corrective and Recovery
Corrective and recovery controls limit damage and return assets to trusted operation. Within security control types and functions, this concept answers a separate question and should retain its own evidence.
Test restoration, access, integrity, timing, and monitoring after recovery. Apply that action to the named case before expanding the investigation or changing protected state.
Respect this boundary: do not call a copy recoverable until restoration succeeds. The required result is specific: the service returns through a verified and documented recovery path.
07
Apply Security Control Types and Functions to One Case
Use the case as a bounded investigation: A small office protects a network closet and its administrator accounts. The team must distinguish governance work, technical enforcement, physical evidence, detection, and restoration.
First, assign accountable roles and preserve evidence that required decisions occurred. Then, configure the mechanism against a stated requirement and test both allow and deny paths. Keep both observations in the case record before choosing the next step.
Next, match barriers, monitoring, and response to the asset and plausible entry path. After that, define the signal, expected context, owner, severity, and investigation path. Finish only after you test restoration, access, integrity, timing, and monitoring after recovery.
08
Recap Before Practice and Prove
Administrative Controls: Administrative controls use policy, planning, training, approval, and review to shape behavior. In practice, assign accountable roles and preserve evidence that required decisions occurred. Preserve the boundary: do not assume a written rule changes behavior without implementation.
Technical Controls: Technical controls use system mechanisms to enforce, detect, or protect an outcome. In practice, configure the mechanism against a stated requirement and test both allow and deny paths. Preserve the boundary: do not measure effectiveness only by installation status.
Physical Controls: Physical controls protect facilities, equipment, media, and environmental conditions. In practice, match barriers, monitoring, and response to the asset and plausible entry path. Preserve the boundary: do not treat a locked door as proof that access is reviewed.
Detective Function: A detective control reveals activity or state that requires interpretation and response. In practice, define the signal, expected context, owner, severity, and investigation path. Preserve the boundary: do not treat an alert as proof of compromise.
Corrective and Recovery: Corrective and recovery controls limit damage and return assets to trusted operation. In practice, test restoration, access, integrity, timing, and monitoring after recovery. Preserve the boundary: do not call a copy recoverable until restoration succeeds.