Detective Control
What is Detective Control?
A security control designed to identify and alert on security events, policy violations, or anomalous activities after they have occurred.
Frameworks that govern detective control
What the standards actually require on detective control
Requirements naming detective control across 3 standards, quoted from the control text.
Logging, monitoring, anomaly detection, and EDR with documented coverage and tuning.
FFIEC-CAT-CC-3 · Cybersecurity Controls - Detective Controls →Implement preventive and detective controls commensurate with the potential impact of data being compromised, establishing risk tolerance and selecting controls to bring risk within the risk appetite.
ADMF-5.1 · Implement risk-based protection controls →The IRM Risk Management Process is a 5-stage continuous cycle aligned closely with ISO 31000:2018 + COSO ERM 2017. (1) Risk Identification: systematic identification of risks through workshops + interviews + SWOT/PESTLE analysis + scenario analysis + bow-tie a...
IRM-Process-Identification-Analysis-Evaluation-Treatment-Monitoring-Review-ISO31000-Aligned · IRM Risk Management Process - 5-Stage Cycle + Identification + Analysis (Inherent/Residual) + Evaluation + Treatment (4Ts Tolerate/Treat/Transfer/Terminate) + Monitoring + Review + Communication + Risk Register →Questions people ask about detective control
What is Detective Control?
Why is Detective Control important for compliance?
Which compliance frameworks address Detective Control?
Where can I learn more about Detective Control?
See how Detective Control applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.