IT Control Classification
IT Control Classification
ForIT RiskManagement
Administrative
Type Technical Physical
/Managerial /Directive
• Firewalls • Change Management • Fences
• Antivirus • Quality Assurance • Locks
• Endpoint Detection and • Segregation of Duties • Man Trap for Entry
Response (EDR) • Job Rotation Doors
• Extended Detection and • Security Awareness • Fire Suppression
Preventive Response (XDR) Training
• Email Gateway • Safety Training
• Intrusion Prevention
System (IPS) and Web
Application Firewall
(WAF)
• System Login Banner • Security Awareness • Fences
• Monitoring Tools • Policies and Standards • Security Cameras
Deterrent • Exit Interview • Warning Banners
• Non-Disclosure
Agreement
• SIEM Solution • Audit • Motion Sensors
• Intrusion Detection • Security Review • Laser Beam
Detective • Vulnerability Scanners • Mandatory Leaves • Video Cameras
• Quality Control • Smoke Detectors
• Security Alarm System
• Backup and Recovery • Incident Response Plan • Fire Suppression
• Network Isolation • Disaster Recovery Plan
Corrective