📖 What is Detective Control?

Detective controls are measures designed to identify errors, irregularities, or security incidents *after* they have occurred. These controls do not prevent issues but provide timely notification, allowing for investigation and corrective action to mitigate potential damage or loss. Examples include log monitoring and reconciliation.

🥋 Sensei Says:

"While important, detective controls are less effective than preventive controls. The exam will test your ability to assess the limitations of detective controls and the importance of timely responses to identified issues. Understand how detective controls complement preventive and corrective controls."

📚 Certification: Certified Information Systems Auditor (CISA)

🔑 What are the Key Concepts of Detective Control?

  • Detective controls rely on identifying anomalies; their effectiveness hinges on timely monitoring and analysis of logs, alerts, and reports.
  • These controls are reactive, meaning they function *after* an event, unlike preventive controls which aim to stop events from happening.
  • Effective detective controls require clearly defined thresholds and escalation procedures to ensure appropriate responses to detected issues.
  • Detective controls are often used to validate the effectiveness of preventive controls, confirming they are functioning as intended.
  • Examples include intrusion detection systems (IDS), security information and event management (SIEM) systems, and regular data reconciliations.

🎯 How does Detective Control appear on the CISA Exam?

You may be asked to evaluate a control framework and identify which controls are primarily detective in nature, versus preventive or corrective.

A scenario might describe a security breach that went undetected for an extended period – expect questions about the adequacy of existing detective controls.

Expect questions about the limitations of detective controls in mitigating risk, and how they should be combined with other control types for a robust security posture.

❓ Frequently Asked Questions

How do detective controls relate to incident response?

Detective controls are the *trigger* for incident response. They identify the event, and incident response procedures dictate the subsequent actions to contain, eradicate, and recover from the incident.


Can a control be both detective and preventive?

Rarely, but some controls have dual functionality. For example, a firewall can *prevent* unauthorized access (preventive) and *log* attempted intrusions (detective), but its primary function dictates its classification.


What’s the difference between a detective control and an audit?

Audits are periodic evaluations, while detective controls are ongoing monitoring. An audit *uses* detective control outputs (like logs) as evidence, but isn’t a continuous control itself.

Related Terms from Certified Information Systems Auditor

📝 Related Study Guides

Deep Dive 10 min read

CISA Exam: What to Expect and How to Prepare in 2026

The CISA exam consists of 150 multiple-choice questions to be completed in 4 hours, requiring a scaled score of 450/800 to pass. Preparation requires mastering five domains focusing on IT auditing, governance, acquisition, operations, and asset protection. Success depends on a risk-based mindset and understanding frameworks like COBIT.

Deep Dive 10 min read

Mastering COBIT 2019 for the CISA Exam

COBIT 2019 is a comprehensive framework for the governance and management of enterprise IT. For CISA candidates, it provides the essential structure to evaluate how an organization aligns IT goals with business objectives, manages risk, and ensures value delivery through a clear distinction between governance and management activities.

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

🧠

Test Your Knowledge

Think you understand Detective Control? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium