Deterrent Control
A deterrent control is a security measure intended to discourage people from attempting to violate security policies or take unauthorized actions. Rather than physically blocking an action, it works by making a potential intruder or insider think twice before proceeding. A common example is a warning sign indicating that an area is private property or under surveillance.
A deterrent control is a control category whose purpose is to reduce the likelihood of a deliberate policy violation or attack by discouraging the actor from attempting it, typically influencing behavior rather than technically preventing the action. Deterrent controls can take various forms, including tangible objects, signage, or the presence of personnel, and they aim to make unauthorized or risky actions less appealing to users, external attackers, or insiders. They are commonly distinguished from preventive controls, which are designed to stop an action from occurring; a deterrent may overlap in effect but relies on discouragement rather than enforcement, and its efficacy depends on the actor's perception and decision-making. In control frameworks, deterrent controls are one of several control types selected and combined according to the risk being addressed.
Why it matters
Deterrent controls address a dimension of risk that purely technical measures often miss: the decision-making of a potential attacker or insider before an action is ever attempted. By reducing the likelihood of a deliberate policy violation, they aim to influence behavior rather than block it outright. This makes them a complementary layer within a broader control set, working alongside preventive, detective, and corrective controls rather than replacing them.
In the context of a SOC 2 examination or an ISO 27001 ISMS, deterrent controls are typically evaluated as part of a defense-in-depth approach rather than as standalone safeguards. Because their efficacy depends on the actor's perception and decision-making, they cannot be relied upon to guarantee that unauthorized actions will not occur. An auditor or certification body assessing such controls will generally consider how they combine with enforcing controls to address a specific risk, and their inclusion in scope depends on the risk being addressed and the scoping decisions made for the engagement.
A key limitation to communicate to stakeholders is that a deterrent control discourages but does not enforce. A warning sign or the visible presence of personnel may reduce the appeal of an attempt, but it does not physically or technically stop a determined actor. For this reason, deterrent controls are most meaningful when documented and understood as one element among several selected and combined according to the risk.
Who it's relevant to
Inside Deterrent Control
Common questions
Answers to the questions practitioners most commonly ask about Deterrent Control.