A Catalogued Control Environment for Security Operations: Applying the Detect-Deter-Delay-Deny-Defend-Defeat Methodology
Introduction
ISO 18788:2015 requires security organizations to establish structured, effective, and auditable controls across their Security Operations Management System (SOMS). To achieve this, many organizations adapt methodologies from ISO 27002 (Information Security Controls)—particularly Clause 7, which addresses physical and environmental security.
When combined with the Detect-Deter-Delay-Deny-Defend-Defeat methodology, organizations can build a catalogued control environment that ensures risks are managed through a layered, measurable, and cost-effective strategy.
The Detect-Deter-Delay-Deny-Defend-Defeat Framework in Practice
- Detect - Identify threats or incidents at the earliest stage.
- Controls: CCTV, alarms, guard patrols, anomaly detection, access log reviews.
- Deter - Discourage potential adversaries from acting.
- Controls: Visible signage, uniformed guards, perimeter fencing, lighting.
- Delay - Slow intrusions long enough for response to occur.
- Controls: Bollards, barriers, multi-gate access, security glazing.
- Deny - Prevent unauthorized access outright.
- Controls: Biometric systems, high-security locks, layered authentication, network segmentation (for integrated ICT/physical security).
- Defend - Engage the threat to minimize harm.
- Controls: Security response teams, incident protocols, law enforcement coordination.
- Defeat - Neutralize threats permanently to ensure they cannot recur.
- Controls: Arrest, prosecution, contractual penalties for non-compliance, long-term remediation and redesign.
Catalogued Control Environment (Modelled on ISO 27002, Clause 7)
A catalogued control environment lists available controls under structured domains, ensuring that each risk can be addressed by one or more suitable measures. Below is a simplified catalogue for Physical Security Controls:
|
Control Category |
Examples of Controls |
Control Strategy (Preventive / Detective / Corrective) |
Layer (Detect → Defeat) |
|
Perimeter Security |
Fencing, barriers, bollards, security lighting, CCTV on perimeter |
Preventive, Detective |
Deter, Detect, Delay |
|
Access Control |
Guard stations, biometric entry, key-card systems, visitor registers |
Preventive, Detective |
Deny, Detect |
|
Monitoring & Surveillance |
CCTV (real-time & recording), intrusion detection, drones, patrols |
Detective |
Detect, Deter |
|
Physical Asset Protection |
Safes, cages, security containers, tamper-proof seals |
Preventive, Delay |
Delay, Deny |
|
Workplace & Facility Security |
Security zoning, mantraps, security glazing, lockdown procedures |
Preventive, Corrective |
Delay, Deny, Defend |
|
Incident Response |
Emergency response teams, escalation protocols, coordination with law enforcement |
Corrective, Preventive |
Defend, Defeat |
|
Community & Stakeholder Engagement |
Grievance mechanisms, awareness campaigns, liaison forums |
Preventive, Corrective |
Deter, Defend |
This catalogue ensures every control is classified, not just listed. It explains:
- Why it exists (risk linkage).
- What strategy it belongs to (preventive, detective, corrective).
- Where it fits in the Detect → Defeat continuum.
Measuring Effectiveness with ICE
Every control in the catalogue must be measured against the Internal Control Effectiveness (ICE) model:
- Excellent (≥90%) - Fully reliable and effective.
- Good (70-89%) - Effective but with minor weaknesses.
- Satisfactory (60-69%) - Partially effective, gaps evident.
- Weak (≤50%) - Exists but largely ineffective.
- No Control - Absent.
This moves the catalogue from a “list of controls†to a measured assurance framework, enabling leadership to prioritize improvements and avoid costly investments in controls that add little real value.
Combined Assurance for Security Controls
Controls must be validated through multiple lines of assurance:
- Management - Daily operation of controls.
- Risk & Compliance - Oversight and testing.
- Internal Audit - Independent verification.
- External Auditors / Certification Bodies - ISO 18788 certification and regulatory compliance.
- Clients & Communities - Demonstration of trust and accountability.
This ensures no single line of defence is relied upon in isolation, building confidence for boards, clients, and regulators.
Conclusion
A Security Controls Catalogue, modelled on ISO 27002 and aligned with the Detect-Deter-Delay-Deny-Defend-Defeat methodology, provides a structured, measurable, and strategic framework for managing risks in security operations.
By classifying controls (Preventive, Detective, Corrective), measuring them with ICE, and embedding them in a Combined Assurance Model, organizations avoid costly “vendor-driven†investments and instead build layered, risk-based, and auditable protection.
This not only satisfies the requirements of ISO 18788 but also enhances credibility, resilience, and trust in the security function.