Preventive, Detective and Corrective Controls
In ISO/IEC 27001, controls are measures that modify information security risk. They are commonly classified by function as preventive, detective or corrective. ISO/IEC 27002:2022 formalises this through its control type attribute, which helps organisations build layered, defence-in-depth protection… In ISO/IEC 27001, controls are measures that modify information security risk. They are commonly classified by function as preventive, detective or corrective. ISO/IEC 27002:2022 formalises this through its control type attribute, which helps organisations build layered, defence-in-depth protection. A Lead Auditor must verify that the selected Annex A controls, justified in the Statement of Applicability, balance all three types according to the risk assessment and risk treatment plan required by Clause 6.1. Preventive controls aim to stop an information security incident before it occurs by reducing the likelihood that a threat exploits a vulnerability. Examples include access control policies, multi-factor authentication, encryption, segregation of duties, security awareness training, secure configuration and physical entry controls. They act before an event and are often the most cost-effective, but no preventive control is perfect. Detective controls identify incidents or anomalies while they are happening or after they have occurred, and they raise alerts. Examples include logging and monitoring, intrusion detection systems, security information and event management (SIEM) tools, CCTV, audit trails, log reviews and internal audits. Their value depends on timely review and escalation, because logs that nobody examines provide little assurance. Corrective controls limit the impact of an incident, restore normal operations and address root causes to prevent recurrence. Examples include incident response procedures, restoring data from backups, business continuity and disaster recovery plans, applying patches after a breach and disciplinary processes. At the management system level, Clause 10.2 requires nonconformities to be corrected and their root causes eliminated through corrective action. From an audit perspective, the auditor gathers objective evidence that each control is appropriately designed, implemented and operating effectively. The three types depend on each other. Weak detection undermines correction, and overreliance on prevention leaves the organisation blind to failures. An effective ISMS integrates all three to protect confidentiality, integrity and availability, and it supports continual improvement through the Plan-Do-Check-Act cycle.
Preventive, Detective and Corrective Controls: A Complete Guide for ISO 27001 Lead Auditors
Introduction
For ISO 27001 Lead Auditor candidates, it is essential to understand how security controls are classified by their function, that is, by when and how they act on a security incident. The three classic categories are Preventive, Detective and Corrective controls. ISO/IEC 27002:2022 formally includes this classification as one of its control attributes ("Control type: #Preventive, #Detective, #Corrective"). That makes it directly relevant to how controls in Annex A of ISO/IEC 27001:2022 are designed, implemented and audited.
Why It Is Important
1. Defence in depth: No single control is perfect. A strong ISMS combines controls that stop incidents, controls that spot them, and controls that recover from them. An auditor must be able to judge whether an organisation relies too heavily on one type.
2. Risk treatment: ISO 27001 clause 6.1.3 requires organisations to select controls to treat risks. Preventive controls mainly reduce likelihood. Detective and corrective controls mainly reduce impact by shortening exposure time and restoring operations.
3. Audit evaluation: Lead auditors assess whether controls are adequate and effective. Knowing the type of a control tells you what evidence to look for:
- Preventive: configurations, access rights.
- Detective: logs, alerts, review records.
- Corrective: incident records, restoration tests, corrective action reports.
4. Alignment with ISO 27002:2022 attributes: Each of the 93 controls is tagged with one or more control types. Examiners therefore expect candidates to classify controls correctly.
5. Continual improvement: Corrective controls link to clause 10.2 (Nonconformity and corrective action). However, a corrective control (operational) is different from a corrective action (management system). Exams often test this distinction.
What They Are
1. Preventive Controls
Preventive controls are designed to stop an information security incident before it occurs. They act on threats and vulnerabilities to reduce the likelihood of an event.
Examples:
- Access control policies and role-based access (A.5.15, A.8.3)
- Multi-factor authentication (A.8.5)
- Firewalls and network segregation (A.8.20, A.8.22)
- Encryption (A.8.24)
- Security awareness training (A.6.3)
- Background screening (A.6.1)
- Segregation of duties (A.5.3)
- Physical locks and secure perimeters (A.7.1, A.7.2)
- Malware protection blocking known threats (A.8.7)
- Change management and secure configuration (A.8.32, A.8.9)
2. Detective Controls
Detective controls identify, record and alert on an incident while it is occurring or after it has occurred. They do not stop the event. They make it visible so a response can follow.
Examples:
- Logging (A.8.15) and monitoring activities (A.8.16)
- Intrusion detection systems (IDS)
- CCTV and physical security monitoring (A.7.4)
- Reviews of user access rights (A.5.18)
- Internal audits (clause 9.2) and independent reviews (A.5.35)
- Information security event reporting by staff (A.6.8)
- File integrity monitoring
- Reconciliation of records
- Threat intelligence (A.5.7, which is also preventive and corrective)
3. Corrective Controls
Corrective controls limit damage, restore systems and data to normal operation, and eliminate the cause after an incident has been detected.
Examples:
- Information backup and restoration (A.8.13)
- Incident management planning and response (A.5.24, A.5.26)
- Learning from incidents (A.5.27)
- ICT readiness for business continuity (A.5.30)
- Patching a vulnerability after an exploit
- Disciplinary process (A.6.4)
- Quarantining malware-infected systems
- Revoking compromised credentials
Related categories you may encounter
- Deterrent: discourages attackers, e.g. warning banners and signs. Often grouped with preventive.
- Compensating: an alternative control used when the primary control is not feasible.
- Recovery: a subset of corrective, focused on restoring operations, e.g. disaster recovery.
- Directive: policies and procedures that tell people what to do.
Note that ISO 27002:2022 uses only Preventive, Detective and Corrective as its control type attribute values.
How They Work Together
Think of the incident timeline:
BEFORE the incident: Preventive (stop it).
DURING / AFTER the incident: Detective (find it).
AFTER detection: Corrective (fix it, restore, prevent recurrence).
Example scenario: ransomware.
- Preventive: email filtering, user training and patching block the initial infection.
- Detective: endpoint detection and SIEM alerts flag unusual encryption activity.
- Corrective: isolating infected hosts, restoring from offline backups and conducting a lessons-learned review.
Key principles:
- Multiple types per control: A single control can serve several functions. For example, ISO 27002:2022 tags A.5.7 Threat intelligence as #Preventive #Detective #Corrective. Antivirus prevents known malware, detects infections and can clean or quarantine files.
- Balance: An organisation with strong preventive controls but no detection may suffer long undetected breaches. One with detection but no correction cannot recover.
- Effectiveness depends on the response: A detective control is only valuable if alerts are reviewed and acted upon. Unreviewed logs are a common audit finding.
- Risk perspective: Preventive controls reduce probability. Detective and corrective controls reduce consequence.
Corrective Control vs Corrective Action (Clause 10.2)
This distinction is critical:
- A correction is the immediate action to fix a nonconformity, e.g. restoring the missing backup.
- A corrective action eliminates the root cause of a nonconformity to prevent recurrence, e.g. automating backup monitoring after root cause analysis.
- A corrective control is a security control that responds to incidents, e.g. a backup restore capability.
ISO 27001:2022 removed "preventive action" as a separate clause. Prevention is addressed through risk-based thinking in clause 6.1, the planning process.
Auditing These Controls
Preventive: Verify design and implementation. Inspect configurations, sample access rights, review training records and test that the controls actually block activity.
Detective: Verify that logs exist, are protected, are reviewed and generate alerts. Look for evidence of review and of escalation to incident management.
Corrective: Review incident records, backup restoration tests, business continuity exercises and lessons-learned reports. Confirm that root causes were addressed.
Exam Tips: Answering Questions on Preventive, Detective and Corrective Controls
1. Ask "WHEN does it act?" If it acts before the incident, it is preventive. If it identifies or alerts during or after, it is detective. If it fixes, restores or limits damage after detection, it is corrective.
2. Look for keywords:
- Preventive: block, stop, restrict, deny, authenticate, encrypt, train, prohibit, segregate.
- Detective: monitor, log, alert, review, audit, identify, discover, reconcile, detect.
- Corrective: restore, recover, repair, patch, remediate, respond, contain, eliminate root cause.
3. Watch for dual-purpose controls. If a question asks for the primary purpose, pick the dominant function. A firewall is primarily preventive, even though its logs are detective. A backup is corrective; the act of taking backups does not prevent data loss, it enables recovery.
4. Don't confuse awareness training. It is preventive, because it reduces the likelihood of human error.
5. Audits and reviews are detective. Internal audits, management reviews and access reviews identify problems; they do not prevent them.
6. Distinguish correction, corrective action and corrective control. In scenario questions on nonconformities, the answer requiring root cause analysis is the corrective action, not just the correction.
7. Scenario questions on adequacy: If a scenario shows logs collected but never reviewed, the finding is that the detective control is ineffective. If backups are never tested, the corrective control has not been verified. Nonconformities are typically raised against clause 9.1 or the relevant Annex A control, as referenced in the Statement of Applicability.
8. Risk link: If asked which control type reduces likelihood, answer preventive. If asked which reduces impact or duration, answer detective and/or corrective.
9. Know the ISO 27002:2022 attributes. The five attribute types are Control type, Information security properties, Cybersecurity concepts, Operational capabilities and Security domains. The Control type values are exactly #Preventive, #Detective and #Corrective.
10. Eliminate distractors. Options such as "directive" or "deterrent" may appear. Choose them only if the question explicitly uses that framework. In an ISO 27001 context, stick to the three official types.
11. In essay or scenario answers, recommend a balanced set: at least one preventive, one detective and one corrective control for the risk described. Reference the relevant Annex A control numbers and say what audit evidence you would request.
12. Remember the auditor's role. Auditors do not design controls. They evaluate whether selected controls are appropriate to the assessed risks, are implemented as documented and are effective. Frame your answers around evidence and conformity.
Quick Memory Aid
Prevent = Protect before.
Detect = Discover during or after.
Correct = Cure and recover after.
Summary
Preventive, detective and corrective controls form a layered approach to managing information security risk. ISO/IEC 27002:2022 makes this classification an official control attribute, and a Lead Auditor must use it to evaluate whether an ISMS has balanced and effective controls. In the exam, identify when the control acts, look for keywords, recognise multi-purpose controls, and separate operational corrective controls from management-system corrective actions.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!