---
title: The importance of keeping security controls up-to-date | Bawn
description: Security controls are safeguards or countermeasures to avoid, detect, counteract, or minimize security risks. Be sure to update them!
image: https://bawn.com/hubfs/Imported_Blog_Media/key-fob-2.jpg
---

[Skip to main content](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/importance-of-security-controls#main)

[![Logo Transparency-1 (1)](https://bawn.com/hs-fs/hubfs/Logo%20Transparency-1%20(1).png?width=230&height=66&name=Logo%20Transparency-1%20(1).png)](https://bawn.com)

- Show submenu for Cyber Risk Engineering Cyber Risk Engineering 
  
    - [What is Cyber Risk Engineering](https://bawn.com/what-is-cyber-risk-engineering)
    - [Cybersecurity vs Cyber Risk Engineering](https://bawn.com/cybersecurity-vs-cyber-risk-engineering)
    - [The Bawn Risk Engineering Framework](https://bawn.com/cyber-risk-engineering-framework)
    - [Cyber Risk Assessment](https://bawn.com/get-your-cyber-risk-score)
    - [Cyber Liability Exposure](https://bawn.com/understand-liability-exposure)
- Show submenu for Services Services 
  
    - Show submenu for Cyber Risk Services Cyber Risk Services 
      
          - [Risk Assessment](https://bawn.com/cybersecurity-risk-assessment-service)
          - [Security Strategy Development](https://bawn.com/cyber-security-strategy-development-services)
          - [Cyber Risk Mitigation](https://bawn.com/risk-mitigation-services)
          - [vCISO](https://bawn.com/vciso-virtual-chief-information-security-officer)
          - [Incident Response Planning](https://bawn.com/incident-response-planning-services)
    - Show submenu for Managed Services Managed Services 
      
          - [A Different Kind of MSP](https://bawn.com/bawn-is-a-different-msp)
          - [Full Service Secure IT](https://bawn.com/msp-services)
    - [Cyber Warranty](https://bawn.com/cyber-warranty)
    - Show submenu for Sectors Sectors 
      
          - [Energy and Utilities](https://bawn.com/energy-and-utilities)
          - [Manufacturing](https://bawn.com/manufacturing)
          - [Startups](https://bawn.com/cyber-services-for-startups)
          - [SMBs](https://bawn.com/smb-cybersecurity)
          - [Financial Services](https://bawn.com/financial-services-cybersecurity)
- [Blog](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond)

Open main navigation

Close main navigation

- Show submenu for Cyber Risk Engineering Cyber Risk Engineering 
  
    - Cyber Risk Engineering
    - [What is Cyber Risk Engineering](https://bawn.com/what-is-cyber-risk-engineering)
    - [Cybersecurity vs Cyber Risk Engineering](https://bawn.com/cybersecurity-vs-cyber-risk-engineering)
    - [The Bawn Risk Engineering Framework](https://bawn.com/cyber-risk-engineering-framework)
    - [Cyber Risk Assessment](https://bawn.com/get-your-cyber-risk-score)
    - [Cyber Liability Exposure](https://bawn.com/understand-liability-exposure)
- Show submenu for Services Services 
  
    - Services
    - Show submenu for Cyber Risk Services Cyber Risk Services 
      
          - Cyber Risk Services
          - [Risk Assessment](https://bawn.com/cybersecurity-risk-assessment-service)
          - [Security Strategy Development](https://bawn.com/cyber-security-strategy-development-services)
          - [Cyber Risk Mitigation](https://bawn.com/risk-mitigation-services)
          - [vCISO](https://bawn.com/vciso-virtual-chief-information-security-officer)
          - [Incident Response Planning](https://bawn.com/incident-response-planning-services)
    - Show submenu for Managed Services Managed Services 
      
          - Managed Services
          - [A Different Kind of MSP](https://bawn.com/bawn-is-a-different-msp)
          - [Full Service Secure IT](https://bawn.com/msp-services)
    - [Cyber Warranty](https://bawn.com/cyber-warranty)
    - Show submenu for Sectors Sectors 
      
          - Sectors
          - [Energy and Utilities](https://bawn.com/energy-and-utilities)
          - [Manufacturing](https://bawn.com/manufacturing)
          - [Startups](https://bawn.com/cyber-services-for-startups)
          - [SMBs](https://bawn.com/smb-cybersecurity)
          - [Financial Services](https://bawn.com/financial-services-cybersecurity)
- [Blog](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond)
- Search
- [Get Started](https://bawn.com/contact-bawn)

[Get Started](https://bawn.com/contact-bawn)

Search

# The importance of keeping security controls up-to-date

May 10, 2023

**Tags:** 

[Security Best Practices](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/tag/security-best-practices)

Today I am visiting the DMV for the second time in my quest to exchange my out-of-state license for a Texas driver’s license. Like many others, I didn’t have all the required documentation with me during the first visit. Part of Texas’ licensing process is to verify the applicant’s SSN. Acceptable documents included a Social Security Card and various other documents such as a W-2, pay stub, and other documents and ID cards with the SSN displayed.

The IRS document I provided during my first visit wasn’t accepted. I pointed out to the person helping me that most of the other listed documents and ID cards no longer show Social Security Numbers due to identity theft concerns – my current and former employers didn’t list SSNs on their employee documents, and the only option would be the actual Social Security Card.

So, I am returning today with a decades-old card that is easily replicated. After investigating Nigerian fraud organizations for a few years, I saw how anyone with a color printer, some heavy linen paper, and an Exacto knife could easily duplicate a Social Security card.

Security controls are safeguards or countermeasures to avoid, detect, counteract, or minimize security risks. Every control put in place can be quantified in the level of risk it decreases and the amount of “friction,” or inconvenience experienced by users when they encounter the control. With the insistence that the actual Social Security card is provided to conduct transactions, this control created a great deal of friction while lowering the risk of identity theft only slightly. This requirement would have been more effective years ago, before the widespread use of high-quality color printers.

Industrial Control Systems can become increasingly vulnerable to cyber threats during their life span.

Security controls could fall into one of the following categories:

- **Physical controls**: doors, locks, security cameras
- **Procedure controls:**incident response processes, management oversight, security awareness and training, background checks for personnel who handle critical systems
- **Technical controls:**user authentication (login) and logical access controls, antivirus software, firewalls
- **Legal and regulatory controls**: policies & standards

Security controls can also be classified according to the time that they act, relative to a security incident:

- Before the event: **preventative controls**are intended to stop an incident from occurring (An example is locking out unauthorized users)
- During the event: **detective controls**are intended to identify and characterize an incident in progress (An example is sounding the intruder alarm and alerting the appropriate personnel such as system administrators, security guards, or law enforcement)
- After the event: **corrective controls** are intended to limit the extent of damage caused by an incident (such as restoring a system to normal working status as fast as possible)

### **Types of security controls that can easily fall out of date**

**ActiveX controls** – ActiveX was a popular technology several years ago, making it possible for websites to provide certain types of content, such as videos and games, and allowing users to interact with certain types of elements in the browser, such as toolbars. Unfortunately, too many ActiveX exposed unsafe functionality.

**Account passwords** – Only changing passwords on a rotational basis or allowing simple passwords exposes accounts to easy compromise. Complex passphrases are a step in the right direction, but Multi-Factor Authentication (MFA) should be used to prevent access to sensitive data. Implementing (MFA) is one of the most cost-effective security controls facing an ever-increasing cyber threat.

**Obsolete software** – Software needs to be continually updated and patched to reduce security vulnerabilities. But what about when patches and updates are no longer available when software continues to be used after a manufacturer discontinues support? Transitioning to newer software may provide operational gains while increasing resilience.

**Obsolete products** – Most consumers transition to new products every few years. Industrial Control Systems are often kept in service for decades, and organizations must ensure that compensating controls are put in place to safeguard their infrastructure.

Even if your client organization has developed the most comprehensive set of security controls, they are effective only as long as their environment stays static. As soon as a change happens within their environment (which will inevitably happen), they will need to reevaluate their controls. When the organization rolls out a new process, technology, or operating procedures (such as allowing employees to work from home due to COVID-19), they need to assess whether the inherent risk that their business faces have increased and update their internal controls accordingly. Personnel who are Certified Information Security Auditors (CISA) or Certified Protection Professional (CPP through the American Society for Industrial Security (ASIS)) or a certified Physical Security Professional (PSP through ASIS) can carry out this endeavor.

A sustainable compliance program is needed to monitor new risks, test and document controls, and guide remediation efforts to mitigate risks effectively and on an ongoing basis.

### Related Articles

##### [![Best Practices for Reviewing SOC 2 Reports](https://bawn.com/hs-fs/hubfs/Shutterstock_2339588021.jpg?width=520&height=294&name=Shutterstock_2339588021.jpg) Security Best Practices • November 27, 2023 Best Practices for Reviewing SOC 2 Reports 4 min read](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/best-practices-for-reviewing-soc-2-reports)

##### [![Ensuring Email Security: A Guide to DKIM, SPF, and DMARC](https://bawn.com/hs-fs/hubfs/Shutterstock_1803527689%20(4).jpg?width=520&height=294&name=Shutterstock_1803527689%20(4).jpg) Security Best Practices • November 09, 2023 Ensuring Email Security: A Guide to DKIM, SPF, and DMARC 2 min read](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/ensuring-email-security-a-guide-to-dkim-spf-and-dmarc)

### Comments

![ancient-scroll (1)](https://bawn.com/hs-fs/hubfs/ancient-scroll%20(1).png?width=110&height=110&name=ancient-scroll%20(1).png)

### Cyber Knowledge Awaits

Stay ahead of cyber threats and gain valuable insights by subscribing to Bawn's blog today!

First Name

Last Name

Email \*

###### Recent Posts

- [Responsible AI Isn’t Optional: Why the Next Few Years Matter More Than Ever](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/responsible-ai-isnt-optional-why-the-next-few-years-matter-more-than-ever)
- [Why Insurance Innovation Is Really About Understanding Risk—Not Avoiding It](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/why-insurance-innovation-is-really-about-understanding-risk-not-avoiding-it)
- [Navigating Compliance in the Age of Cybersecurity: Insights from Kate Williams](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/navigating-compliance-in-the-age-of-cybersecurity-insights-from-kate-williams)
- [Why Your Business Continuity Plan Should Be Part of Your Cyber Risk Strategy](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/why-your-business-continuity-plan-should-be-part-of-your-cyber-risk-strategy)
- [A Cyber Playbook for Non-Tech Executives](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/a-cyber-playbook-for-non-tech-executives)

[![Logo Transparency-2 (1)](https://bawn.com/hs-fs/hubfs/Logo%20Transparency-2%20(1).png?width=300&height=87&name=Logo%20Transparency-2%20(1).png)](https://bawn.com/placeholder)

- Company 
    - [About Bawn](https://bawn.com/about-us)
    - [Our Approach to Cyber Risk](https://bawn.com/cyber-services-for-startups-4)
    - [Our Services](https://bawn.com/cyber-services-for-startups)
    - [Career](https://bawn.com/careers)
    - [Our Partners](https://bawn.com/partners)
    - [Privacy Policy](https://bawn.com/privacy-policy)
    - [Terms and Conditions](https://bawn.com/terms-and-conditions)
    - [Master Services Agreement](https://bawn.com/master-services-agreement)
- Get Help 
    - [Blog](https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond)
    - [CPA Toolkit](https://bawn.com/cpa-trusted-advisor)
    - [FAQ](https://bawn.com/frequently-asked-questions)
    - [Contact Us](https://bawn.com/contact-bawn)
- Affiliate Program 
    - [For Insurance Agents & Brokers](https://bawn.com/insurance-agent-affiliate-program)
    - [Affiliate Program Terms and Conditions](https://bawn.com/bawn-affiliate-terms-and-conditions-program-)
- Crushing It 
    - [Podcast Episodes](https://bawn.com/crushing-it)
    - [Guest Signup](https://bawn.com/crushing-it/guest-signup)

©2026 Bawn, Inc. All rights reserved.

 

- <https://www.linkedin.com/company/bawn>
- <https://www.twitter.com/BawnHQ>
- <https://www.youtube.com/@BawnCyber>
- <https://www.facebook.com/bawncyber>

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Bawn",
    "url" : "https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/author/bawn"
  },
  "dateModified" : "2024-03-05T17:38:00.264Z",
  "datePublished" : "2023-05-10T21:48:53.000Z",
  "headline" : "The importance of keeping security controls up-to-date | Bawn",
  "image" : [ "https://bawn.com/hubfs/Imported_Blog_Media/key-fob-2.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://bawn.com/risk-resilience-bawns-guide-to-cybersecurity-and-beyond/importance-of-security-controls",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://bawn.com/hubfs/Logo%20Transparency-1%20(1)-1.png"
    },
    "name" : "Bawn"
  }
}
```