Skip to main content
Category: Control Types and Framework

Detective Control

Also known as: detective control activity
Simply put

A detective control is a safeguard designed to identify problems, errors, or irregularities after they have already occurred, rather than stopping them in advance. Once an issue is detected, it can be investigated and corrected. Common examples include logging, monitoring, and alerting mechanisms that flag unusual activity for follow-up.

Formal definition

A detective control is a control activity designed to discover and enable the timely correction of an unintended event, error, or irregularity after it has occurred, typically by detecting, logging, and alerting on the condition. In security and compliance contexts, detective controls (such as monitoring, log review, and alerting) complement preventive controls and are frequently assessed for both design suitability and operating effectiveness in a SOC 2 Type II examination, and may map to reference controls selected in an ISO/IEC 27001 Statement of Applicability. The presence of a detective control does not guarantee that all events are identified; its effectiveness depends on scope, configuration, and the review procedures applied.

Why it matters

Detective controls address a fundamental reality of security and compliance: no set of preventive measures stops every problem. Errors, misconfigurations, and malicious activity will sometimes get through, and the ability to discover those issues after they occur determines how quickly an organization can investigate and correct them. This is why detective controls such as logging, monitoring, and alerting are treated as a foundational part of a control environment rather than an optional add-on, they provide the visibility needed to catch what preventive controls miss.

In a SOC 2 Type II examination, detective controls are frequently assessed for both design suitability and operating effectiveness over the review period, meaning an auditor looks not only at whether monitoring and alerting mechanisms are designed appropriately but also at whether they operated as intended throughout the engagement. In an ISO/IEC 27001 context, detective controls may correspond to reference controls selected through the Statement of Applicability, informed by the organization's risk assessment. Because these frameworks differ in structure and outcome, the way a detective control is documented and evidenced can vary depending on which framework and scope applies.

It is important to recognize the limits of these controls. The presence of a detective control does not guarantee that every event is identified; its effectiveness depends on scope, configuration, and the review procedures applied. A logging mechanism that captures the wrong data, or an alert that no one reviews, may satisfy a documentation requirement while failing to deliver actual detection value, which is precisely why operating effectiveness, and not just design, is examined in most engagements.

Who it's relevant to

Compliance Managers and GRC Professionals
Those responsible for mapping controls to framework requirements need to document how detective controls are implemented and evidenced. In an ISO/IEC 27001 program, this may mean reflecting detective controls in the Statement of Applicability as informed by risk assessment; for SOC 2, it means ensuring these controls are in scope and supported by the evidence an examination will require.
Auditors and Assessors
In a SOC 2 Type II examination, detective controls are frequently assessed for both design suitability and operating effectiveness over the defined review period. Assessors evaluate not only whether monitoring, logging, and alerting mechanisms are designed appropriately but also whether they operated as intended throughout the period covered.
Security Engineers
Engineers who build and maintain monitoring, log review, and alerting capabilities are the practitioners who determine whether a detective control actually detects. Because effectiveness depends on scope, configuration, and the review procedures applied, engineering decisions about what to capture and how to route alerts directly shape the control's real-world value.

Inside Detective Control

Purpose
A detective control is designed to identify and detect security events, errors, anomalies, or control failures after they have occurred, enabling timely response and remediation.
Distinction from Preventive Controls
Unlike preventive controls, which aim to stop an event before it happens, detective controls operate to surface events that have already taken place, often working in tandem with preventive and corrective controls as part of a layered approach.
Common Examples
Typical detective controls include log monitoring, security information and event management (SIEM) alerting, intrusion detection systems, audit trail reviews, access reviews, and anomaly detection, though the specific mix depends on scope and risk.
Relevance to SOC 2
In a SOC 2 examination, detective controls may support several Trust Services Criteria, including the Security category (Common Criteria). A SOC 2 Type II report assesses whether such controls operated effectively over the defined review period, while a Type I assesses only the suitability of their design at a point in time.
Relevance to ISO 27001
Within an ISO/IEC 27001 ISMS, detective controls may be selected as Annex A reference controls through the Statement of Applicability, informed by risk assessment. The specific control references and their organization differ between the 2013 and 2022 revisions of the standard.

Common questions

Answers to the questions practitioners most commonly ask about Detective Control.

Does implementing a detective control mean you can skip preventive controls?
No. Detective controls identify events after they occur, while preventive controls aim to stop events from happening in the first place. The two serve different purposes and are typically deployed together as complementary layers rather than as substitutes. Relying only on detection leaves gaps that preventive measures are designed to close, and most control environments combine both categories depending on scope and risk.
Is a detective control the same thing as a corrective control?
No. A detective control identifies that an event or anomaly has occurred, whereas a corrective control acts to remediate or restore conditions after detection. Detection surfaces the issue; correction responds to it. They are often chained together in a control workflow, but they are distinct functions and are generally documented separately when describing how controls address a given risk.
How are detective controls evaluated in a SOC 2 Type II examination versus a Type I?
In a SOC 2 Type I, a detective control is assessed for suitability of design at a point in time, meaning the auditor considers whether the control is designed appropriately to detect the relevant events. In a Type II, the same control is assessed for both design and operating effectiveness over a defined review period, so evidence typically must show that the detection activity operated consistently throughout that period. The period length is set by scoping decisions rather than being fixed.
How do detective controls relate to the Trust Services Criteria in a SOC 2 engagement?
Detective controls commonly map to the Security category (the Common Criteria), which is required in every SOC 2 engagement, and may also support optional categories such as Availability, Processing Integrity, Confidentiality, or Privacy when those are included in scope. The specific criteria a detective control addresses depend on the scoping decisions made for the engagement, so the mapping varies rather than following a single universal rule.
Where do detective controls fit within an ISO 27001 ISMS?
Within an ISO 27001 ISMS, detective controls are typically selected from the Annex A reference controls via the Statement of Applicability, informed by the organization's risk assessment. The certifiable ISMS requirements themselves reside in clauses 4 through 10. Whether a particular detective control is included depends on the risk assessment outcomes and the defined scope of the ISMS, so applicability varies by organization.
What evidence typically demonstrates that a detective control is operating effectively?
Evidence generally focuses on showing that the detection activity occurred and produced actionable output over the relevant period. Depending on scope and the auditor's or certification body's expectations, this may include records that the monitoring or review took place, that anomalies were identified, and that they were routed for response. Because requirements depend on the engagement scope, applicable criteria, and the assessor, the specific evidence expected varies and should be confirmed for each engagement.

Common misconceptions

Detective controls prevent security incidents from occurring.
Detective controls do not prevent incidents; they identify events that have already occurred. Prevention is the function of preventive controls, and detective controls typically complement rather than replace them.
Implementing detective controls guarantees that a SOC 2 report or ISO 27001 certificate confirms the organization is free from breaches.
A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined scope of the ISMS. Detective controls improve the ability to identify events but do not eliminate risk.
A detective control that satisfies SOC 2 automatically satisfies ISO 27001, and vice versa.
Mapping between the two frameworks is possible but partial. Satisfying a Trust Services Criterion does not automatically satisfy an Annex A reference control or the ISMS requirements in clauses 4 through 10, since the frameworks have distinct structures and evaluation methods.

Best practices

Define the intended detection outcome for each control and document how it identifies specific events, errors, or anomalies within your scope.
For SOC 2 Type II engagements, retain evidence demonstrating that detective controls operated consistently over the defined review period, not just that they were designed appropriately.
When applying detective controls in an ISO 27001 ISMS, tie their selection to the risk assessment and record the rationale in the Statement of Applicability, specifying the standard version in use.
Pair detective controls with corresponding response and remediation processes so that detected events lead to timely action rather than remaining unaddressed.
Review the effectiveness of detective controls periodically, adjusting monitoring thresholds and coverage as scope, risk, and applicable criteria evolve.
Avoid treating detective controls as a substitute for preventive controls; use them as part of a layered approach appropriate to your engagement and scope.