Guide

Understanding Security Controls

Preventive, detective, corrective, administrative, technical, physical — what the categories mean and why it matters when you write narratives.

Intended audience
Anyone new to compliance vocabulary
Difficulty
Beginner
Estimated time
10 minutes
Access
Free
NIST CSF
NIST SP 800-53
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Classify controls by function: preventive, detective, and corrective.
  • Classify controls by type: administrative, technical, and physical.
  • Give an example of each functional control category.
  • Explain why a program needs a balance of functional categories.
  • Apply control categorization when writing SSP narratives.

By function

  • Preventive: stops something happening (MFA, least privilege).
  • Detective: tells you it happened (log review, alerting).
  • Corrective: restores after (backups, incident response).

By type

  • Administrative: policies, training, reviews.
  • Technical: configurations and tooling.
  • Physical: locks, badges, secure storage.

Why the categories help

If every control you claim is preventive and technical, you probably cannot detect or recover from anything — and an assessor will notice.

Key takeaways

  • Preventive controls stop something from happening, such as multi-factor authentication or least privilege.
  • Detective controls tell you that something happened, such as log review or alerting.
  • Corrective controls restore the environment after an incident, such as backups or incident response.
  • Administrative, technical, and physical are the three control types, covering policies, tooling, and physical safeguards respectively.
  • A program relying only on preventive, technical controls likely cannot detect or recover from incidents, which assessors will notice.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 3
Knowledge check

80% required to pass. Answers are graded on our servers.

1. What is an example of a preventive control?

2. What is a detective control?

3. What is a corrective control?

4. Which of the following is a control 'type' rather than a 'function'?

5. What happens if a program relies solely on preventive, technical controls?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This resource is educational readiness material. ComplianceAnvil is not a certification authority, assessor, or law firm, and this content is not legal advice or a compliance assessment.

Matched on shared frameworks, topics, and program packs.

Template

Acceptable Use Policy

What employees may and may not do with company systems, data, devices, and AI tools.

Beginner
25 min
Free
NIST CSF

Published · v1.0.0 · 2026-08-01

Template

Annual Review Checklist

The once-a-year pass that keeps a program from quietly going stale.

Beginner
30 min
Free
NIST CSF
ISO 27001

Published · v1.0.0 · 2026-08-01

Template

Backup Verification Log

Proof that backups exist, run, and have actually been restored at least once.

Beginner
15 min
Free
NIST CSF
CIS Controls

Published · v1.0.0 · 2026-08-01

Exercise

Complete a Readiness Scorecard

Score yourself honestly across six areas and turn the two lowest into a short plan.

Beginner
15 min
Free
NIST CSF

Published · v1.0.0 · 2026-08-01

Quick reference

Compliance Acronyms — One Page

The acronyms that appear in contracts and assessments, defined in one line each.

Beginner
5 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Quick reference

Compliance Project Timeline — One Page

A realistic phase-by-phase timeline for a small business standing up a program.

Beginner
5 min
Free
NIST CSF
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.