UNIVERSITY OF MARYLAND GLOBAL CAMPUS • UMGC • CMIT 320
CMIT 320 Guide: How to Choose a Security Control for a Given Threat
Choose a security control by tracing a bounded threat mechanism through the relevant vulnerability or exposure to a protected security objective. Define what the control must accomplish, compare appropriate administrative, technical, or physical families, and test each candidate for coverage, timing, feasibility, dependencies, limitations, and evidence of effectiveness. The best control is not the strongest-sounding product. It is the proportionate response that changes the identified path, preserves the mission, works with complementary layers, and leaves an explicit residual-risk and monitoring decision.
Decision resource
Security-Control Selection Decision Aid
A seven-criterion comparison aid covering objective fit, coverage, timing, feasibility, dependencies, adverse effects, and verifiability.
Step 1
- criterion
- Objective fit
- decision question
- Which part of the bounded threat path changes?
- evidence
- Mechanism-to-control rationale
- failure signal
- Only a control name is supplied
Step 2
- criterion
- Coverage and timing
- decision question
- Who, what, and which operating states are covered when it matters?
- evidence
- Scope and response timing
- failure signal
- Important paths or moments are unexamined
Step 3
- criterion
- Feasibility and dependencies
- decision question
- Can the safeguard be operated and maintained under stated assumptions?
- evidence
- Ownership, skills, data, integration, and maintenance
- failure signal
- The decision assumes perfect operation
Step 4
- criterion
- Limitations and effects
- decision question
- What remains and what burden can the safeguard create?
- evidence
- Failure modes, friction, cost, and mission effects
- failure signal
- The recommendation claims complete protection
Step 5
- criterion
- Verifiability
- decision question
- Which evidence shows operation and effectiveness?
- evidence
- Indicator, test, owner, and trigger
- failure signal
- Deployment count is the only measure
Translate the threat label into a decision question
Broad labels such as malware, social engineering, insider risk, or service disruption are not precise enough to select a safeguard. A student should identify the protected fictional asset, security objective, general mechanism, and exposure condition. The mechanism remains high level and non-operational. Ask which change would reduce opportunity, detect the event, limit the consequence, restore capability, or compensate for a constraint. This produces a control objective. For example, a fictional organization worried about unreliable record changes may need to constrain who can authorize a change and detect unexpected exceptions before downstream use. The decision is not simply choose access control. It is determine which preventive and detective functions address the specific integrity path, what evidence they need, and which limitations remain. This keeps CMIT 320 distinct from generic networking or product configuration.
Compare control families and functions
Administrative, technical, and physical families describe how a safeguard is established. Preventive, detective, corrective, and compensating labels describe what it primarily does in the scenario. Both views matter. A technical control may prevent an action, detect a condition, or support correction. An administrative process can prevent inconsistent behavior and detect exceptions through review. A physical safeguard can prevent access or delay an event long enough for detection and response. Compare candidates by the objective they meet, the part of the path they affect, the evidence they produce, and the complementary layer they require. Do not assume a technical answer is automatically more rigorous. If the exposure is unclear ownership, training, exception handling, or approval, governance may be central. If the exposure is unenforced authorization, technical enforcement may be central. The recommendation should explain the relationship rather than merely classify the control.
Evaluate fit, coverage, feasibility, and limitations
The Security-Control Selection Decision Aid uses seven criteria. First, objective fit: does the candidate change the relevant mechanism or consequence? Second, coverage: which assets, users, paths, and operating states are included? Third, timing: does the safeguard act before, during, or after the event when it matters? Fourth, feasibility: can the fictional organization operate and maintain it? Fifth, dependencies: which identity, data, staffing, facility, or technology assumptions must hold? Sixth, adverse effects: what cost, friction, delay, false-positive load, or mission impact can result? Seventh, verifiability: which indicator or test shows the safeguard works? A candidate can be useful without scoring perfectly. The decision should compare tradeoffs and explain why the selected combination is proportionate. Absolute claims usually signal that limitations have not been examined.
Compare a primary control with alternatives
A defensible recommendation considers at least one plausible alternative or companion. The purpose is not to create a shopping list. It is to reveal why one response better fits the stated objective and which gap another layer may address. A primary preventive control may offer strong reduction but depend on consistent identity data. A detective review may cover exceptions but act later and require staff capacity. A corrective process may limit consequence but not reduce opportunity. A compensating control may be acceptable during a transition but weaker or more costly over time. Explain the consequence of not selecting an alternative and the conditions under which the decision should change. This comparison also exposes common-mode failure. If both candidates depend on the same data or team, apparent diversity may not provide real resilience.
Fictional scenario: protecting a volunteer portal
A fictional nonprofit uses a portal to coordinate volunteers. The protected objectives are appropriate confidentiality for contact details and availability during scheduled events. The bounded threat mechanism is inappropriate access through excessive permissions; the exposure is inconsistent role review after volunteers change responsibilities. The control objective is to reduce unnecessary access and detect review exceptions. An administrative role-owner process addresses responsibility, a technical role boundary enforces approved access, and a detective review identifies stale assignments. A purely physical safeguard would not fit the logical path, while awareness alone would not enforce the decision. Limitations include inaccurate role data, delayed offboarding, emergency exceptions, and dependence on review quality. Residual risk remains from authorized misuse and role-owner error. Monitoring includes completion, exception age, and sampled access accuracy. No instructions for bypassing the portal are needed to explain why the controls fit.
Include residual risk and monitoring in the selection
Control selection is incomplete if it ends at implementation. State the remaining scenario after the expected change. Explain which limitations create it, which owner can accept or reduce it, and what evidence will trigger reassessment. Measures should reflect operation and effectiveness, not just presence. A completed review rate may show operation; the age and accuracy of exceptions may better reveal effectiveness. A restoration test may show corrective capability; the time to restore shows whether it meets the mission need. Avoid unsupported numeric certainty. Use a qualitative residual statement when evidence does not justify precision. This habit turns a one-time recommendation into a defensible security-management decision.
Write a compact control-selection record
A compact decision record makes the reasoning auditable. State the fictional asset and objective, bounded mechanism and exposure, control objective, selected family and function, plausible alternative, expected effect, dependencies, adverse effects, limitations, residual risk, owner, indicator, and reassessment trigger. Each field should be short but connected. If the selected safeguard does not change the stated mechanism or exposure, revise the control objective. If the limitation has no effect on the residual statement, the analysis is incomplete. If the indicator proves only installation, choose evidence closer to operation or outcome. This record helps a CMIT 320 student explain the decision instead of listing features.
Avoid three common control-selection errors
First, do not treat a broad threat label as sufficient scope; identify the protected objective and exposure. Second, do not assume the most restrictive candidate is automatically proportionate; compare coverage, mission effect, feasibility, and dependencies. Third, do not hide uncertainty behind a score. When reliable numeric evidence is unavailable, state a bounded qualitative judgment and explain what evidence would change it. These checks keep the recommendation defensible. They also preserve the defensive-only boundary because the analysis concerns control objectives, fit, limitations, and monitoring rather than instructions for testing a real target.
Distinguish control capability from evidence of effectiveness
A description of what a safeguard can do establishes capability, not effectiveness in the fictional scenario. Effectiveness evidence must connect to the control objective. If the objective is reducing unauthorized change, useful evidence may include coverage, exception quality, review timing, and sampled accuracy. If the objective is recovery, restoration success and time matter more than the existence of a copy. If the objective is detection, signal relevance, review ownership, and response timing matter more than raw alert volume. State what the indicator can and cannot prove. A low exception count may indicate strong prevention, incomplete observation, or low activity; context is necessary. This distinction helps a CMIT 320 student avoid confusing implementation evidence with risk reduction.
Explain how constraints change the preferred response
Control selection takes place within mission, staffing, time, cost, usability, legal, physical, and technical constraints. A constraint does not excuse a weak recommendation; it changes the comparison. The preferred response may be phased, paired with a temporary compensating process, narrowed to the highest-priority assets, or supported by stronger monitoring. Explain the exposure that persists during the constraint and set an owner and end condition. Avoid treating a compensating safeguard as permanently equivalent without evidence. The conclusion should show why the response is proportionate now and which changed fact would support a different choice later.
Use the decision aid without surrendering authorship
Write the scenario and objective in your own words, compare candidates using the seven criteria, and draft the residual-risk statement. Then check the logic against current classroom instructions. Domyclass can point out a control that does not address the stated mechanism, a missing limitation, or a measure that proves only deployment. It will not select a control for a live organization, provide exploit detail, or write a completed plan for submission. The embedded aid is educational; no separate interactive tool route is created by this work.
Related CMIT 320 resources
Get Help With CMIT 320 Network Security at University of Maryland Global Campus
Get targeted CMIT 320 help and improve your grades.
Get CMIT 320 HelpSources & updates
- University of Maryland Global Campus: Course Information: Network Security (CMIT 320)
- University of Maryland Global Campus: Online Cybersecurity Technology Bachelor’s Degree
- University of Maryland Global Campus: Online Computer Networking & Cybersecurity Undergraduate Certificate
- National Institute of Standards and Technology: CSRC Glossary: Residual Risk
- National Institute of Standards and Technology: CSRC Glossary: Defense in Depth
Published by Domyclass • Updated August 2026