Managerial controls
Over site of a system
Risk identification, strategy, evaluation and selection of security controls
Operational controls
Controls for the human element
Policies, procedures and training programs
Technical controls
Implemented using systems
Preventative control
Designed to prevent an occurrence
Security guard or a firewall
Detective control
Designed to detect a security incident
IDS
Corrective
Mitigates damage
IPS or backups
Deterrent control
A login banner or signs
Compensating control
Restores using other means
Backup power system
Control categories
Operational
Managerial
Technical