Anything which is used to protect an asset
In security, control is anything used to reduce risk of an asset
Data is an asset
We cannot touch it – logical asset
But has value
Eg: lock and key
Prevention (before events) detective(during event) corrective( after
event)
Physical
(something we
can touch)
logical
(non human
Intervention/
Not touchable)
Administrative
(human admin)