A Catalogued Control Environment for Security Operations: Applying the Detect-Deter-Delay-Deny-Defend-Defeat Methodology

Introduction

ISO 18788:2015 requires security organizations to establish structured, effective, and auditable controls across their Security Operations Management System (SOMS). To achieve this, many organizations adapt methodologies from ISO 27002 (Information Security Controls)—particularly Clause 7, which addresses physical and environmental security.

When combined with the Detect-Deter-Delay-Deny-Defend-Defeat methodology, organizations can build a catalogued control environment that ensures risks are managed through a layered, measurable, and cost-effective strategy.

The Detect-Deter-Delay-Deny-Defend-Defeat Framework in Practice

  1. Detect - Identify threats or incidents at the earliest stage.
    • Controls: CCTV, alarms, guard patrols, anomaly detection, access log reviews.
  2. Deter - Discourage potential adversaries from acting.
    • Controls: Visible signage, uniformed guards, perimeter fencing, lighting.
  3. Delay - Slow intrusions long enough for response to occur.
    • Controls: Bollards, barriers, multi-gate access, security glazing.
  4. Deny - Prevent unauthorized access outright.
    • Controls: Biometric systems, high-security locks, layered authentication, network segmentation (for integrated ICT/physical security).
  5. Defend - Engage the threat to minimize harm.
    • Controls: Security response teams, incident protocols, law enforcement coordination.
  6. Defeat - Neutralize threats permanently to ensure they cannot recur.
    • Controls: Arrest, prosecution, contractual penalties for non-compliance, long-term remediation and redesign.

Catalogued Control Environment (Modelled on ISO 27002, Clause 7)

A catalogued control environment lists available controls under structured domains, ensuring that each risk can be addressed by one or more suitable measures. Below is a simplified catalogue for Physical Security Controls:

Control Category

Examples of Controls

Control Strategy (Preventive / Detective / Corrective)

Layer (Detect → Defeat)

Perimeter Security

Fencing, barriers, bollards, security lighting, CCTV on perimeter

Preventive, Detective

Deter, Detect, Delay

Access Control

Guard stations, biometric entry, key-card systems, visitor registers

Preventive, Detective

Deny, Detect

Monitoring & Surveillance

CCTV (real-time & recording), intrusion detection, drones, patrols

Detective

Detect, Deter

Physical Asset Protection

Safes, cages, security containers, tamper-proof seals

Preventive, Delay

Delay, Deny

Workplace & Facility Security

Security zoning, mantraps, security glazing, lockdown procedures

Preventive, Corrective

Delay, Deny, Defend

Incident Response

Emergency response teams, escalation protocols, coordination with law enforcement

Corrective, Preventive

Defend, Defeat

Community & Stakeholder Engagement

Grievance mechanisms, awareness campaigns, liaison forums

Preventive, Corrective

Deter, Defend

This catalogue ensures every control is classified, not just listed. It explains:

  • Why it exists (risk linkage).
  • What strategy it belongs to (preventive, detective, corrective).
  • Where it fits in the Detect → Defeat continuum.

Measuring Effectiveness with ICE

Every control in the catalogue must be measured against the Internal Control Effectiveness (ICE) model:

  • Excellent (≥90%) - Fully reliable and effective.
  • Good (70-89%) - Effective but with minor weaknesses.
  • Satisfactory (60-69%) - Partially effective, gaps evident.
  • Weak (≤50%) - Exists but largely ineffective.
  • No Control - Absent.

This moves the catalogue from a “list of controls” to a measured assurance framework, enabling leadership to prioritize improvements and avoid costly investments in controls that add little real value.

Combined Assurance for Security Controls

Controls must be validated through multiple lines of assurance:

  • Management - Daily operation of controls.
  • Risk & Compliance - Oversight and testing.
  • Internal Audit - Independent verification.
  • External Auditors / Certification Bodies - ISO 18788 certification and regulatory compliance.
  • Clients & Communities - Demonstration of trust and accountability.

This ensures no single line of defence is relied upon in isolation, building confidence for boards, clients, and regulators.

Conclusion

A Security Controls Catalogue, modelled on ISO 27002 and aligned with the Detect-Deter-Delay-Deny-Defend-Defeat methodology, provides a structured, measurable, and strategic framework for managing risks in security operations.

By classifying controls (Preventive, Detective, Corrective), measuring them with ICE, and embedding them in a Combined Assurance Model, organizations avoid costly “vendor-driven” investments and instead build layered, risk-based, and auditable protection.

This not only satisfies the requirements of ISO 18788 but also enhances credibility, resilience, and trust in the security function.