Security Controls Explained

  • Firewalls
    Firewalls

    Preventative control

    Firewalls are often the first line of defence in a network. But what does a firewall actually do?

  • Access Controls
    Access Controls

    Preventative control

    Access Controls are used to decide who, or what is allowed to access your building, systems, applications, data, and more.

  • MFA
    MFA

    Preventative control

    Passwords only provide one form of security – if they are compromised, it’s game over. MFA requires more than just a password

  • Network Segmentation
    Network Segmentation

    Preventative control

    Don’t allow attackers to roam freely inside your network. Isolate key parts with network segmentation.

  • Encryption
    Encryption

    Preventative control

    Encryption protects data by converting it into a form that only those with the right key can unlock it.

  • Application Allowlisting
    Application Allowlisting

    Preventative control

    Application Allowlisting ensures that only approved, trusted code is allowed to execute.

  • Hardening
    Hardening

    Preventative control

    Hardening is the process of reducing the attack surface of a system to make is more difficult for an attacker to gain entry or control.

  • Patch management
    Patch management

    Preventative control

    Patch management is the process of ensuring all your systems are protected as best they can be from all threat types.

  • Input Validation
    Input Validation

    Preventative control

    Input Validation prevents damage to a system by ensuring that the data received is valid, trusted, and safe.

  • Password policies
    Password policies

    Preventative control

    Password policies are designed to help organisations manage the access credentials lifecycle.

  • Logging & Auditing
    Logging & Auditing

    Detective control

    Logging & Auditing provides an organisation the ability to gather data about the who, what, where, and when of events in their network.

  • SIEM, SOAR & EDR
    SIEM, SOAR & EDR

    Detective control

    SIEM, SOAR & EDR are the eyes, ears and response within a corporate network. They gather and analyse activity data and make decisions on how to respond.

  • IDS/IPS
    IDS/IPS

    Detective control

    IDS/IPS -Intrusion Detections Systems & Intrusion Prevention Systems help organisations indenify and stop unauthorised, or malicious activity.

  • EUBA
    EUBA

    Detective control

    EUBA – Entity and User Behaviour Analytics helps organisations determine if unusual activity is happening in their network

  • Honeypots & Honeynets
    Honeypots & Honeynets

    Detective control

    Honeypots & Honeynets are designed to attract attackers in order to allow security analysts the ability to see what the attacker is doing.

  • Incident Response
    Incident Response

    Corrective control

    Incident response is the organised process used to identify, investigate, contain, eradicate and recover from security incidents. Security controls try to prevent incidents. Incident response deals with them when they happen.

  • Malware removal
    Malware removal

    Corrective control

    Malware removal is not simply a case of deleting the bad file – it is a carefully managed process of identification, isolation, evidence gathering, recovery, and ensuring it doesn’t happen again.

  • Account recovery
    Account recovery

    Corrective control

    Account recovery is a managed process that allows legitimate users the ability to regain entry to their systems, but keeps attacker out.

  • System restoration
    System restoration

    Corrective control

    System restoration is the controlled process of returning a system to a known, trusted, and operational state – It’s not just about fixing a problem.

  • Policies
    Policies

    Deterrent control

    Policies define what is expected, protect our systems, and keep the organisation secure. They also deter people from performing unauthorised activities.

  • Visible security
    Visible security

    Deterrent control

    Visible security acts as a deterrent to would be attackers. IT shows that an organisation takes its security seriously. CCTV, guards, warning signs, secure doors and windows tells an attacker – don’t bother – try somewhere else.

  • Compensating controls
    Compensating controls

    Compensating control

    A compensating control is something put in place when the ideal security control isn’t possible. We cannot ignore risk just because a control isn’t available – something must be put in place to manage the risk.