Security Controls Matrix
A Quick Reference Guide for Control Types and Functions
Preventive:Stop threats
Detective:Identify incidents
Corrective:Fix & recover
Control Type | Preventive | Detective | Corrective |
---|---|---|---|
Physical |
|
|
|
Technical |
|
|
|
Administrative |
|
|
|
How They Interlace
This matrix shows that every security control has both a TYPE (how it's implemented) and a FUNCTION (what it does). For example:
- A firewall is a Technical control with a Preventive function.
- CCTV cameras are Physical controls with a Detective function.
- Incident response teams are Administrative controls with a Corrective function.
Key Integration Points
- Defense in Depth: Use multiple control types for each function.
- Comprehensive Coverage: Ensure all 9 cells have appropriate controls.
- Control Dependencies: Some controls rely on others (e.g., SIEMs need logs).
- Risk-Based Selection: Choose controls based on your specific risk profile.
- Regular Review: Periodically assess if your control matrix has gaps.