The Security Controls Catalogue: Defining Preventive, Detective, and Corrective Strategies

Introduction

In modern security operations, organizations face an ever-growing catalogue of available controls—ranging from policies, procedures, and human resource measures to high-tech surveillance, biometric access systems, and AI-powered tools. However, not all controls are created equal, and not all are necessary. Too often, product-driven security companies sell expensive systems—such as advanced locks or biometric scanners—without considering the actual risks they are intended to address, or the strategic role of the control in the wider risk treatment methodology.

A professional Security Operations Management System (SOMS), aligned with ISO 18788:2015, avoids this trap by classifying each control according to its function: Preventive, Detective, or Corrective. This ensures that investments are aligned with risks, integrated into a broader control strategy, and measured for effectiveness through methodologies like Internal Control Effectiveness (ICE).

The Purpose of a Security Controls Catalogue

A Security Controls Catalogue provides a structured list of all available controls, categorized by:

  • Control Type - Preventive, Detective, or Corrective.
  • Control Domain - Governance, Operations, HR, Technology, Assets, Compliance, Stakeholder Engagement.
  • Associated Risks - The specific risks the control is designed to treat.
  • Effectiveness Level - Measured through ICE scoring.
  • Cost Profile - CAPEX vs. OPEX for implementation and sustainability.

Such a catalogue prevents ad hoc or product-driven decision-making and instead promotes a risk-based, evidence-driven approach.

Control Strategies in the Security Environment

1. Preventive Controls

Purpose: Reduce the likelihood of a risk event occurring.

Examples:

  • Vetting and background checks for new employees.
  • Access control systems (locks, biometric scanners, card readers).
  • Security awareness training.
  • Deployment procedures and rules of engagement.

Role in Risk Treatment:

Preventive controls are the first line of defense. They aim to stop an incident before it happens, but they require continuous investment (OPEX) and maintenance to remain effective.

Warning: Over-reliance on expensive preventive products without context (e.g., a “super-locking system”) may give a false sense of security if detective and corrective controls are weak.

2. Detective Controls

Purpose: Identify and alert when a risk event has occurred or is occurring.

Examples:

  • CCTV monitoring with real-time analytics.
  • Intrusion detection systems.
  • Incident reporting mechanisms.
  • Patrol logs and compliance audits.

Role in Risk Treatment:

Detective controls do not prevent incidents, but they are crucial for early identification, allowing rapid response. They also provide audit trails and evidence for accountability.

Warning: A company that invests heavily in locks (preventive) but ignores CCTV and monitoring (detective) may never know whether controls are actually working.

3. Corrective Controls

Purpose: Limit the impact of an incident and restore normal operations.
Examples:

  • Incident response procedures.
  • Grievance mechanisms and community remediation processes.
  • Insurance policies and liability coverage.
  • Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP).

Role in Risk Treatment:
Corrective controls provide resilience and recovery, ensuring that even if incidents occur, damage is minimized and operations are restored quickly.

Warning: Organizations that ignore corrective controls often face catastrophic consequences after a breach, even if preventive and detective measures were strong.

Integrating Controls into Risk Treatment Methodology

In ISO 18788 and ISO 31000, risk treatment requires evaluating multiple options: avoid, reduce, transfer, or accept the risk. Controls are the mechanisms for implementing these treatments.

The methodology is:

  1. Identify the risk.
  2. Define risk criteria (likelihood, consequence, ICE).
  3. Select the appropriate mix of controls:
    • Preventive to reduce likelihood.
    • Detective to ensure early warning.
    • Corrective to minimize impact.
  4. Measure effectiveness through ICE scoring and combined assurance.
  5. Review CAPEX/OPEX balance to ensure sustainability.

Why Control Strategy Matters More Than Products

Security product vendors often promote expensive preventive controls (e.g., advanced locking systems, biometric scanners) as “silver bullets.” However, without a clear understanding of:

  • The risk context (internal and external, Clause 4 of ISO 18788).
  • The control strategy (preventive, detective, corrective).
  • The measurement of effectiveness (ICE scoring).

…these purchases risk becoming costly white elephants that look impressive but add little to overall assurance.

By contrast, a well-balanced control strategy that blends preventive, detective, and corrective measures provides layered defence, aligns with international best practice, and delivers real, measurable value.

Conclusion

The Security Controls Catalogue is not just a list of tools—it is a strategic framework for selecting, classifying, and measuring controls. By distinguishing between preventive, detective, and corrective strategies, organizations can ensure that every control is fit for purpose, contextually relevant, and cost-justified.

The failure to understand control strategy leads to misplaced investments—often driven by vendors selling high-cost preventive solutions without regard to actual risks. Instead, organizations must adopt a risk-based, internationally aligned methodology (ISO 18788, ISO 31000, ISO 27002) and measure controls through ICE and Combined Assurance mapping.

This ensures that controls are not only present and visible, but also effective, sustainable, and auditable—delivering real assurance to clients, regulators, and communities.