Preventive Control
What is Preventive Control?
A security control designed to stop a security incident or policy violation from occurring in the first place, such as access controls or input validation.
Frameworks that govern preventive control
What the standards actually require on preventive control
Requirements naming preventive control across 3 standards, quoted from the control text.
Network segmentation, secure configuration baselines, and change management to prevent compromise.
FFIEC-CAT-CC-1 · Cybersecurity Controls - Preventive Controls Infrastructure Management →Identify preventive controls and develop recovery strategies per NIST SP 800-34 Rev 1 Section 3.3 (Identify Preventive Controls) + Section 3.4 (Create Contingency Strategies).
NISTSP34-3 · Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment →The IRM Risk Management Process is a 5-stage continuous cycle aligned closely with ISO 31000:2018 + COSO ERM 2017. (1) Risk Identification: systematic identification of risks through workshops + interviews + SWOT/PESTLE analysis + scenario analysis + bow-tie a...
IRM-Process-Identification-Analysis-Evaluation-Treatment-Monitoring-Review-ISO31000-Aligned · IRM Risk Management Process - 5-Stage Cycle + Identification + Analysis (Inherent/Residual) + Evaluation + Treatment (4Ts Tolerate/Treat/Transfer/Terminate) + Monitoring + Review + Communication + Risk Register →Questions people ask about preventive control
What is Preventive Control?
Why is Preventive Control important for compliance?
Which compliance frameworks address Preventive Control?
Where can I learn more about Preventive Control?
See how Preventive Control applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.