Defensive Security Controls
- Technical controls - System hardening 
- Sanitize user input/parameterize 
- Administrative controls 
- - Multifactor authentication 
- - Encryption - 
- - Process-level remediation 
- - Patch management 
- - Key rotation 
- - Certificate management 
- - Secrets management solution 
- - Network segmentation 
- - Infrastructure security controls 
 
- Physical controls - Access control vestibule 
- Biometric controls 
- Video surveillance 
 
- Operational controls - Job rotation 
- Time-of-day restrictions 
- Mandatory vacations 
- User training 
 
- Administrative Controls - Role-based access control 
- Secure software development life cycle 
- Minimum password requirements 
- Policies and procedures 
 
Last updated
Was this helpful?