Data Protection Security Controls - Satori

Data Protection Security Controls

In this chapter, we’ll take a broad look at security controls related to data security, discuss what they are and their significance to maintaining security in an organization. The following topics will be covered:

  1. What are Security Controls
  2. Types of Security Controls
  3. Combining Security Controls
  4. Common Security Controls in Cybersecurity
  5. What are the Primary Objectives of Data Security Controls?
  6. Assessing Security Controls for Data Protection
  7. Implementing Security Controls for Data Protection?

What are Security Controls?

Broadly speaking, security controls are any safeguards or countermeasures that are used to prevent, reduce, counteract or detect security risks. This concept can be applied in any field. For example, car alarms, barbed wires and CCTV are security controls that protect physical entities in the physical world. In cybersecurity, this can entail firewalls, endpoint protection and data protection solutions.

In many cases, a single security control will achieve more than one action (i.e. it can both reduce risks as well as detect and alert you to potential breaches).

Types of Security Controls

Security controls are typically classified according to their main value against security risks, which can be divided into the following three categories:

The CIA triad addresses security controls broadly as well:

Combining Security Controls

In many cases, it is best to deploy security controls in a layered approach as they are insufficient when deployed individually. Consider the effectiveness of a fence built around a perimeter as a preventative measure against unauthorized access. Although effective against many types of penetration, it cannot prevent an adversary from digging under it or destroying it to access the asset you mean to protect. A combination of several controls, set up according to strategic specifications, is required to actually secure the perimeter. This may require adding a CCTV to detect risks and deploying a security team to counteract breaches.

Information security works along similar lines. In most cases, placing a single security control cannot address all of the risks enterprises face, especially when the protected assets in question are also dynamic in nature (given that data is usually subject to constant change). This means that organizations must (1) prevent unauthorized access to data, (2) monitor authorized access against anomalies (i.e: fraud) and (3) counteract breaches (meaning install processes for incident response).

Common Security Controls in Cybersecurity

The cybersecurity industry is full of different kinds of cybersecurity controls and is producing new ones regularly. The most common found among enterprises are the following:

What are the Primary Objectives of Data Security Controls?

The primary objectives of data security controls are to prevent, detect and provide corrective measures for the risks and threats faced by organizational data. This includes:

Assessing Security Controls for Data Protection

A good approach to assessing the effectiveness of security controls for data measures is to map out the entirety of an organization’s data stores, focusing on those holding the most sensitive data, and modeling the most pressing threats to be reduced or eliminated. The frameworks listed below can provide further insight into carrying this out.

The following parameters should be considered when selecting the right security controls for your organizational data protection:

TCO: The total cost of ownership is an important consideration that takes into account the usage, infrastructure costs, training and professional services required to keep the solution effective.

Implementing Security Controls for Data Protection?

The implementation of security controls is often challenging. It can be helpful to implement the following advice: