Learning Objectives
By the end of this digital training module, you will be able to:
- Examine the unique operational roles played by the six functional control types.
- Analyze enterprise threat vectors and match proper mitigative countermeasures.
- Design defense-in-depth frameworks by aligning sequential functional security barriers.
Introduction
In cybersecurity, knowing *who* enforces a control is only half the battle. To build resilient networks, we must categorize controls based on **their job during a security incident**.
These roles are classified into six **Functional Types**. Organizing controls by function allows systems engineers to structure multiple defense boundaries, ensuring that if a threat breaches our prevention barrier, detection and corrective triggers are already waiting.
The Six Functional Types
Hover, click, or tap each card below to flip it and explore its operational objective, core focus, and real-world implementations.
Preventive
Proactive DefenseDesigned to actively block, deter, or stop a security incident before it can materialize or damage systems.
Examples:Firewall Rules, Mantraps, Biometric Locks, System Hardening
Detective
Incident VisibilityDesigned to identify, trace, register, and alert security operations of an intrusion attempt or operational anomaly.
Examples:Intrusion Detection Systems (IDS), CCTV, Security Audit Log Audits
Corrective
Response & RecoveryDesigned to actively minimize impact, rebuild system configurations, and restore stability after an exploit.
Examples:Disaster Recovery Backups, IPS Block Rules, Active Incident Remediation
Deterrent
Psychological DecoyDesigned to discourage adversaries, increase perceived efforts, and visually signal defensive strength.
Examples:High-Visibility Guard Towers, "Under CCTV Monitoring" Signs, Decoy Targets
Directive
Policy MandateDesigned to govern organizational behavior, establish rules of conduct, and ensure standards compliance.
Examples:Acceptable Use Policy (AUP), GDPR regulatory frameworks, NDAs
Compensating
Fallback MeasureDesigned as temporary or alternative protections when standard controls are unavailable, impossible, or too costly.
Examples:Hot sites, manual paper ledgers during terminal power outages, temporary security guards
Interactive Activity 1: The Tactical Functional Matching Challenge
Determine the correct functional control type for each enterprise scenario. Achieve a perfect match!
Interactive Activity 2: Defense-In-Depth Architect
Deploy a multi-layered security plan. Assign the correct controls to mitigate the incoming threat.
Incoming Threat Scenario
Ransomware Lateral Movement
An attacker has breached an entry workstation and is attempting to deploy encryption payloads across your central servers.
Assessment: Verify Your Knowledge
Complete the 5 multiple-choice questions below to test your operational knowledge of control categories and functions.