📖 What is Preventative Control?
Preventative Control is a security measure implemented to stop a security incident from occurring in the first place. These controls act as a barrier to prevent unauthorized access or malicious activity.
"Firewalls and physical locks are primary examples. If the goal is stopping the event before it starts, it is a preventative control."
📚 Certification: Certified Information Security Manager (CISM)
🔑 What are the Key Concepts of Preventative Control?
- ▸ Proactive Risk Mitigation: Preventative controls aim to reduce the probability of a threat exploiting a vulnerability, effectively stopping the incident before it manifests.
- ▸ Defense-in-Depth Integration: These controls serve as the first line of defense, creating barriers that malicious actors must bypass to reach critical assets.
- ▸ Logical and Physical Implementation: Examples range from technical solutions like firewalls and ACLs to physical measures like biometric locks and security guards.
- ▸ Administrative Preventative Measures: Security awareness training and strict hiring policies act as preventative controls by reducing human error and insider threat risks.
- ▸ Control Hierarchy: In the CISM framework, preventative controls are prioritized to avoid the costs and disruptions associated with incident response and recovery.
🎯 How does Preventative Control appear on the CISM Exam?
You may be asked to identify the most effective control to reduce the likelihood of unauthorized access to a sensitive database, requiring you to choose a preventative measure over a detective one.
A scenario might describe a company experiencing frequent unauthorized entries into a server room; expect to select a preventative control, such as a badge reader, to stop the occurrences.
Expect questions where you must distinguish between a firewall (preventative) and an Intrusion Detection System (detective) when designing a layered security architecture to protect a network.
❓ Frequently Asked Questions
What is the difference between a preventative control and a deterrent control?
Preventative controls physically or logically block an action from occurring. Deterrent controls, such as warning signs or the threat of prosecution, aim to discourage a potential attacker from attempting the action.
Can a single security tool serve as both a preventative and detective control?
While some tools have multiple features, CISM exams typically require you to categorize a control by its primary intent. If the goal is to stop the event, it is preventative.