Detective Control
A detective control is a safeguard designed to identify problems, errors, or irregularities after they have already occurred, rather than stopping them in advance. Once an issue is detected, it can be investigated and corrected. Common examples include logging, monitoring, and alerting mechanisms that flag unusual activity for follow-up.
A detective control is a control activity designed to discover and enable the timely correction of an unintended event, error, or irregularity after it has occurred, typically by detecting, logging, and alerting on the condition. In security and compliance contexts, detective controls (such as monitoring, log review, and alerting) complement preventive controls and are frequently assessed for both design suitability and operating effectiveness in a SOC 2 Type II examination, and may map to reference controls selected in an ISO/IEC 27001 Statement of Applicability. The presence of a detective control does not guarantee that all events are identified; its effectiveness depends on scope, configuration, and the review procedures applied.
Why it matters
Detective controls address a fundamental reality of security and compliance: no set of preventive measures stops every problem. Errors, misconfigurations, and malicious activity will sometimes get through, and the ability to discover those issues after they occur determines how quickly an organization can investigate and correct them. This is why detective controls such as logging, monitoring, and alerting are treated as a foundational part of a control environment rather than an optional add-on, they provide the visibility needed to catch what preventive controls miss.
In a SOC 2 Type II examination, detective controls are frequently assessed for both design suitability and operating effectiveness over the review period, meaning an auditor looks not only at whether monitoring and alerting mechanisms are designed appropriately but also at whether they operated as intended throughout the engagement. In an ISO/IEC 27001 context, detective controls may correspond to reference controls selected through the Statement of Applicability, informed by the organization's risk assessment. Because these frameworks differ in structure and outcome, the way a detective control is documented and evidenced can vary depending on which framework and scope applies.
It is important to recognize the limits of these controls. The presence of a detective control does not guarantee that every event is identified; its effectiveness depends on scope, configuration, and the review procedures applied. A logging mechanism that captures the wrong data, or an alert that no one reviews, may satisfy a documentation requirement while failing to deliver actual detection value, which is precisely why operating effectiveness, and not just design, is examined in most engagements.
Who it's relevant to
Inside Detective Control
Common questions
Answers to the questions practitioners most commonly ask about Detective Control.