Defense & Operations
Corrective Controls
Also known as: Remediation controls, Reactive controls
Definition
Security measures that act after an incident to limit damage, eradicate threats, and restore systems to a known-good state.
Examples
- Automatically quarantining a host where ransomware behaviour is detected by EDR.
- Restoring a database from the last clean snapshot after a wiper incident.
Related terms
Preventive Controls
Controls designed to stop a security event from occurring in the first place by removing the opportunity or capability to act.
Detective Controls
Security measures designed to identify and alert on malicious activity, policy violations, or anomalies after they occur in an environment.
Compensating Controls
Compensating Controls — definition coming soon.
Incident Response
The organised process of preparing for, detecting, analysing, containing, eradicating, and recovering from cyber security incidents, then capturing lessons learned.
Mean Time to Recover (MTTR)
Mean Time to Recover (MTTR) — definition coming soon.
Recovery Time Objective (RTO)
Recovery Time Objective (RTO) — definition coming soon.