Skip to content

Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Information Systems

Information Systems Security and Controls: Threats and Types of Controls

Updated 11 October 2026 · Fact-checked

Information systems security protects hardware, software, data and people from threats such as malware, unauthorised access and errors. You do it with controls: general controls cover the whole IT environment, application controls cover each program, and each control is preventive, detective or corrective in nature.

Understand Information Systems Security and Controls

An information system is the set of people, hardware, software, data and procedures a business uses to capture, process, store and report information. If it fails or is misused, the business loses money, data and trust. Security is about keeping that from happening.

Security aims at three goals, called the CIA triad. Confidentiality means only authorised people see the data. Integrity means data stays accurate and complete, and is changed only in approved ways. Availability means the system and data are usable when needed.

A threat is anything that can cause harm, such as malware, hacking, phishing, insider fraud, power failure, fire or human error. A vulnerability is a weakness a threat can use, such as a weak password or unpatched software. Risk is the chance that a threat uses a vulnerability and the loss that follows. A control is a policy, procedure or tool that reduces that risk.

Controls are classified in two ways. By scope: general controls (IT environment wide) and application controls (inside a specific program, covering input, processing and output). By purpose: preventive (stop the event), detective (find it when it happens) and corrective (fix the damage and recover).

In the exam you are expected to name a threat, pick the right control, classify it and say why it fits the facts given. Good answers always link the control to the risk.

Key rules to remember

CIA triad
Security = Confidentiality + Integrity + Availability
Say which of the three goals a threat or control affects.
Risk relationship
Risk = Threat × Vulnerability × Impact (conceptual)
A conceptual link, not a calculation. No threat or no vulnerability means low risk.
Control by scope
IS controls = General controls + Application controls
General: policies, access, change management, operations, backup, physical security. Application: input, processing, output, storage controls.
Control by purpose
Preventive (before) → Detective (during or after) → Corrective (after detection)
Example: firewall prevents, log review detects, backup restore corrects.

How to solve Information Systems Security and Controls questions

Use the same short route for any question on threats and controls. It keeps your answer structured and case-linked.

  1. 1Read the facts and underline the asset, the incident or weakness, and what the question asks (identify, classify, recommend or explain).
  2. 2Name the threat and the vulnerability in one line each.
  3. 3State which CIA goal is affected.
  4. 4Pick the control. Decide if it is general or application, and if it is preventive, detective or corrective.
  5. 5Give one practical implementation point, such as who does what, how often, and what record is kept.
  6. 6Link the control back to the facts and give a clear conclusion.
  7. 7If asked to list, group your points under headings so the marker sees structure.

Quickest way: Threat, Goal, Control, Type

When to use it: Use when time is short or the question asks you to classify or list controls.

  1. Write the four labels: Threat, CIA goal, Control, Type.
  2. Fill one line against each for every item in the question.
  3. Add one case-specific sentence at the end.
  4. For list questions, use the groups: access, input, processing, output, backup, physical, change.

Common mistakes in Information Systems Security and Controls

  • Mixing up general and application controls.

    Both protect the same system, so they feel alike.

    Fix: Ask: does it protect the whole IT environment (general) or one program's transactions (application)? Password policy is general; a validity check on an input field is application.

  • Treating detective and corrective controls as the same.

    Both act after something goes wrong.

    Fix: Detective finds the problem (audit logs, alerts). Corrective fixes it (restore from backup, patching, rerunning a process).

  • Listing controls without linking them to the facts.

    Students memorise lists and write them out.

    Fix: Tie each control to the stated risk in the case, and say what it prevents or detects.

  • Confusing threat, vulnerability and risk.

    Everyday language uses them loosely.

    Fix: Threat is the source of harm, vulnerability the weakness, risk the likelihood and impact combined.

  • Ignoring physical and environmental controls.

    Students think security means only software.

    Fix: Always include access to premises, fire protection, power backup and secure disposal of media.

Worked examples

Example 1

A Pune-based company finds that a former employee still logs in to its payroll system and changes bank details. Identify the threat and suggest general controls, classifying each.

Show the solution
  1. Threat: unauthorised access by a former employee, an insider-type threat. Vulnerability: user accounts not removed on exit.
  2. CIA goal affected: confidentiality and integrity of payroll data.
  3. Control 1: deactivate access on the exit date through an HR-IT exit checklist. General, access control, preventive.
  4. Control 2: review user logs and flag changes to bank details for approval. General, monitoring, detective.
  5. Control 3: restore correct data from backup and reset passwords after the incident. General, corrective.
  6. Conclusion: the root cause is weak access management, so the exit checklist is the key control.

Answer: The threat is unauthorised access through an unremoved account. Use preventive control (timely deactivation), detective control (log review and approval of bank-detail changes) and corrective control (restore from backup and reset credentials). All three are general controls.

Example 2

A billing application accepts an invoice with a negative quantity. List application controls that would have prevented or detected this, with their type.

Show the solution
  1. Identify the stage: the error is at input, so input controls apply.
  2. Preventive: a validity or range check rejects quantity below 1 at entry.
  3. Preventive: mandatory-field and format checks ensure the quantity field is complete.
  4. Detective: an exception report lists unusual invoices for supervisor review.
  5. Processing and output: control totals compare batch totals with the invoice register to detect differences.
  6. Corrective: reverse the wrong invoice through a credit note and re-enter it correctly.

Answer: Use a range or validity check at input (preventive), an exception report and batch control totals (detective), and a reversal with re-entry (corrective). All are application controls, because they work inside the billing program.

Exam tips

  • Always classify a control twice: by scope and by purpose. Markers look for both.
  • Use headings such as General controls and Application controls to make your answer easy to scan.
  • Write case-based answers in order: threat, effect, control, conclusion.
  • Give examples that match the facts, such as Indian companies, payroll, GST invoicing or banking.

Practice questions from Information Systems

Information Systems Security and Controls in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Information Systems Security and Controls: frequently asked questions

What are general controls in information systems?

They are controls that apply across the whole IT environment. Examples are access management, change management, backup and recovery, physical security and IT operations procedures.

What are application controls?

They are controls built into a specific program to ensure that transactions are complete, accurate and authorised. They cover input, processing and output.

What is the difference between preventive, detective and corrective controls?

Preventive controls stop an event before it happens. Detective controls find it when or after it happens. Corrective controls fix the damage and restore normal operations.

Is a firewall a general or an application control?

A firewall protects the network, so it is a general control. It is also preventive, because it blocks unwanted traffic.