Security Control Selection and Gap Analysis
Select preventive, detective, and corrective controls based on risk and perform gap analysis.
Control Types: Preventive, Detective, Corrective
Preventive controls block threats before they succeed (firewalls, access control, encryption). Detective controls identify threats that have occurred (IDS, logging, audits). Corrective controls reduce impact after an incident (backups, IR plans, patches). Layered defense requires all three types.
Control Categories
Controls span multiple dimensions: Physical (locks, cameras), Technical (firewalls, MFA), Administrative (policies, training). For a given risk, select complementary controls across categories — a technical control supported by an administrative policy and physical security creates genuine defense-in-depth.
All lessons in this course
- Threat Modeling with STRIDE and PASTA
- Risk Frameworks: NIST CSF and ISO 27001
- Security Control Selection and Gap Analysis
- Security Audit and Compliance Reviews