Security control selection is the process of choosing appropriate safeguards to reduce risk to an acceptable level. Controls are selected based on the risk assessment results, compliance requirements, and cost-benefit analysis.
Every control must map to a specific threat or vulnerability identified during risk assessment. Applying controls without a risk basis wastes resources and may create a false sense of security.
Always document the rationale for selecting or rejecting a control. Auditors and stakeholders will ask why certain risks were accepted without technical countermeasures.
Verify exercises to earn ★ 120 XP and unlock next lab level.