CyberGlossary

Defense & Operations

Preventive Controls

Also known as: Preventative controls

Definition

Controls designed to stop a security event from occurring in the first place by removing the opportunity or capability to act.

Preventive controls block, deter, or restrict actions before damage occurs. Examples include MFA, encryption, firewalls, network segmentation, principle of least privilege, secure coding, application allowlisting, endpoint hardening, and security awareness training. They are typically the most cost-effective layer because they avoid incidents rather than respond to them, but they cannot be perfect. A defense-in-depth strategy pairs preventive controls with detective and corrective controls so that anything that bypasses prevention is still seen and contained.

Examples

  • Enforcing FIDO2 phishing-resistant MFA on all administrative accounts.
  • Network segmentation that prevents a compromised marketing laptop from reaching the payments environment.

Related terms