📖 What is Preventive Control?
A Preventive Control is a security measure implemented to stop a security incident from occurring in the first place. These controls act as a barrier to prevent unauthorized access, malicious activity, or accidental errors.
"Think of these as 'locks.' Firewalls, security guards, and encryption are preventive. They are generally the most desired controls because they avoid the cost of recovery."
📚 Certification: Certified Information Security Manager (CISM)
🔑 What are the Key Concepts of Preventive Control?
- ▸ Proactive Risk Mitigation: These controls focus on reducing the likelihood of a threat exploiting a vulnerability, effectively stopping the incident before it impacts the organization.
- ▸ Defense-in-Depth Integration: Preventive controls serve as the first line of defense, working alongside detective and corrective controls to create a layered security posture.
- ▸ Technical and Administrative Implementation: Examples range from technical solutions like firewalls and MFA to administrative measures like security awareness training and strict access policies.
- ▸ Cost-Effectiveness of Avoidance: From a CISM perspective, prevention is often prioritized because it eliminates the operational costs and reputation damage associated with incident recovery.
🎯 How does Preventive Control appear on the CISM Exam?
You may be asked to identify the most effective control to reduce the probability of a specific risk occurring, requiring you to distinguish preventive measures from detective ones.
A scenario might describe a requirement to stop unauthorized users from entering a secure area; you must choose a preventive control, such as a biometric lock, over a detective one.
Expect questions where you must evaluate a set of controls and determine which one specifically addresses the 'likelihood' component of the risk equation rather than the 'impact'.
❓ Frequently Asked Questions
What is the difference between a preventive control and a deterrent control?
Preventive controls physically or logically stop an action from happening. Deterrent controls, like warning signs or cameras, aim to discourage a person from attempting the action through fear of consequences.
Can a single security measure be both preventive and detective?
While most controls fit one primary category, some overlap. For example, a firewall prevents unauthorized traffic from entering a network but also logs those attempts, providing a detective capability.
Why shouldn't an organization rely solely on preventive controls?
No preventive control is 100% effective. CISM emphasizes defense-in-depth, ensuring that if a preventive control is bypassed, detective controls identify the breach and corrective controls remediate the damage.