UNIVERSITY OF MARYLAND GLOBAL CAMPUS • UMGC • CMIT 320

CMIT 320 Guide: How to Choose a Security Control for a Given Threat

Choose a security control by tracing a bounded threat mechanism through the relevant vulnerability or exposure to a protected security objective. Define what the control must accomplish, compare appropriate administrative, technical, or physical families, and test each candidate for coverage, timing, feasibility, dependencies, limitations, and evidence of effectiveness. The best control is not the strongest-sounding product. It is the proportionate response that changes the identified path, preserves the mission, works with complementary layers, and leaves an explicit residual-risk and monitoring decision.

Get CMIT 320 Help

Decision resource

Security-Control Selection Decision Aid

A seven-criterion comparison aid covering objective fit, coverage, timing, feasibility, dependencies, adverse effects, and verifiability.

Step 1

criterion
Objective fit
decision question
Which part of the bounded threat path changes?
evidence
Mechanism-to-control rationale
failure signal
Only a control name is supplied

Step 2

criterion
Coverage and timing
decision question
Who, what, and which operating states are covered when it matters?
evidence
Scope and response timing
failure signal
Important paths or moments are unexamined

Step 3

criterion
Feasibility and dependencies
decision question
Can the safeguard be operated and maintained under stated assumptions?
evidence
Ownership, skills, data, integration, and maintenance
failure signal
The decision assumes perfect operation

Step 4

criterion
Limitations and effects
decision question
What remains and what burden can the safeguard create?
evidence
Failure modes, friction, cost, and mission effects
failure signal
The recommendation claims complete protection

Step 5

criterion
Verifiability
decision question
Which evidence shows operation and effectiveness?
evidence
Indicator, test, owner, and trigger
failure signal
Deployment count is the only measure

Translate the threat label into a decision question

Broad labels such as malware, social engineering, insider risk, or service disruption are not precise enough to select a safeguard. A student should identify the protected fictional asset, security objective, general mechanism, and exposure condition. The mechanism remains high level and non-operational. Ask which change would reduce opportunity, detect the event, limit the consequence, restore capability, or compensate for a constraint. This produces a control objective. For example, a fictional organization worried about unreliable record changes may need to constrain who can authorize a change and detect unexpected exceptions before downstream use. The decision is not simply choose access control. It is determine which preventive and detective functions address the specific integrity path, what evidence they need, and which limitations remain. This keeps CMIT 320 distinct from generic networking or product configuration.

Compare control families and functions

Administrative, technical, and physical families describe how a safeguard is established. Preventive, detective, corrective, and compensating labels describe what it primarily does in the scenario. Both views matter. A technical control may prevent an action, detect a condition, or support correction. An administrative process can prevent inconsistent behavior and detect exceptions through review. A physical safeguard can prevent access or delay an event long enough for detection and response. Compare candidates by the objective they meet, the part of the path they affect, the evidence they produce, and the complementary layer they require. Do not assume a technical answer is automatically more rigorous. If the exposure is unclear ownership, training, exception handling, or approval, governance may be central. If the exposure is unenforced authorization, technical enforcement may be central. The recommendation should explain the relationship rather than merely classify the control.

Evaluate fit, coverage, feasibility, and limitations

The Security-Control Selection Decision Aid uses seven criteria. First, objective fit: does the candidate change the relevant mechanism or consequence? Second, coverage: which assets, users, paths, and operating states are included? Third, timing: does the safeguard act before, during, or after the event when it matters? Fourth, feasibility: can the fictional organization operate and maintain it? Fifth, dependencies: which identity, data, staffing, facility, or technology assumptions must hold? Sixth, adverse effects: what cost, friction, delay, false-positive load, or mission impact can result? Seventh, verifiability: which indicator or test shows the safeguard works? A candidate can be useful without scoring perfectly. The decision should compare tradeoffs and explain why the selected combination is proportionate. Absolute claims usually signal that limitations have not been examined.

Compare a primary control with alternatives

A defensible recommendation considers at least one plausible alternative or companion. The purpose is not to create a shopping list. It is to reveal why one response better fits the stated objective and which gap another layer may address. A primary preventive control may offer strong reduction but depend on consistent identity data. A detective review may cover exceptions but act later and require staff capacity. A corrective process may limit consequence but not reduce opportunity. A compensating control may be acceptable during a transition but weaker or more costly over time. Explain the consequence of not selecting an alternative and the conditions under which the decision should change. This comparison also exposes common-mode failure. If both candidates depend on the same data or team, apparent diversity may not provide real resilience.

Fictional scenario: protecting a volunteer portal

A fictional nonprofit uses a portal to coordinate volunteers. The protected objectives are appropriate confidentiality for contact details and availability during scheduled events. The bounded threat mechanism is inappropriate access through excessive permissions; the exposure is inconsistent role review after volunteers change responsibilities. The control objective is to reduce unnecessary access and detect review exceptions. An administrative role-owner process addresses responsibility, a technical role boundary enforces approved access, and a detective review identifies stale assignments. A purely physical safeguard would not fit the logical path, while awareness alone would not enforce the decision. Limitations include inaccurate role data, delayed offboarding, emergency exceptions, and dependence on review quality. Residual risk remains from authorized misuse and role-owner error. Monitoring includes completion, exception age, and sampled access accuracy. No instructions for bypassing the portal are needed to explain why the controls fit.

Include residual risk and monitoring in the selection

Control selection is incomplete if it ends at implementation. State the remaining scenario after the expected change. Explain which limitations create it, which owner can accept or reduce it, and what evidence will trigger reassessment. Measures should reflect operation and effectiveness, not just presence. A completed review rate may show operation; the age and accuracy of exceptions may better reveal effectiveness. A restoration test may show corrective capability; the time to restore shows whether it meets the mission need. Avoid unsupported numeric certainty. Use a qualitative residual statement when evidence does not justify precision. This habit turns a one-time recommendation into a defensible security-management decision.

Write a compact control-selection record

A compact decision record makes the reasoning auditable. State the fictional asset and objective, bounded mechanism and exposure, control objective, selected family and function, plausible alternative, expected effect, dependencies, adverse effects, limitations, residual risk, owner, indicator, and reassessment trigger. Each field should be short but connected. If the selected safeguard does not change the stated mechanism or exposure, revise the control objective. If the limitation has no effect on the residual statement, the analysis is incomplete. If the indicator proves only installation, choose evidence closer to operation or outcome. This record helps a CMIT 320 student explain the decision instead of listing features.

Avoid three common control-selection errors

First, do not treat a broad threat label as sufficient scope; identify the protected objective and exposure. Second, do not assume the most restrictive candidate is automatically proportionate; compare coverage, mission effect, feasibility, and dependencies. Third, do not hide uncertainty behind a score. When reliable numeric evidence is unavailable, state a bounded qualitative judgment and explain what evidence would change it. These checks keep the recommendation defensible. They also preserve the defensive-only boundary because the analysis concerns control objectives, fit, limitations, and monitoring rather than instructions for testing a real target.

Distinguish control capability from evidence of effectiveness

A description of what a safeguard can do establishes capability, not effectiveness in the fictional scenario. Effectiveness evidence must connect to the control objective. If the objective is reducing unauthorized change, useful evidence may include coverage, exception quality, review timing, and sampled accuracy. If the objective is recovery, restoration success and time matter more than the existence of a copy. If the objective is detection, signal relevance, review ownership, and response timing matter more than raw alert volume. State what the indicator can and cannot prove. A low exception count may indicate strong prevention, incomplete observation, or low activity; context is necessary. This distinction helps a CMIT 320 student avoid confusing implementation evidence with risk reduction.

Explain how constraints change the preferred response

Control selection takes place within mission, staffing, time, cost, usability, legal, physical, and technical constraints. A constraint does not excuse a weak recommendation; it changes the comparison. The preferred response may be phased, paired with a temporary compensating process, narrowed to the highest-priority assets, or supported by stronger monitoring. Explain the exposure that persists during the constraint and set an owner and end condition. Avoid treating a compensating safeguard as permanently equivalent without evidence. The conclusion should show why the response is proportionate now and which changed fact would support a different choice later.

Use the decision aid without surrendering authorship

Write the scenario and objective in your own words, compare candidates using the seven criteria, and draft the residual-risk statement. Then check the logic against current classroom instructions. Domyclass can point out a control that does not address the stated mechanism, a missing limitation, or a measure that proves only deployment. It will not select a control for a live organization, provide exploit detail, or write a completed plan for submission. The embedded aid is educational; no separate interactive tool route is created by this work.

Get Help With CMIT 320 Network Security at University of Maryland Global Campus

Get targeted CMIT 320 help and improve your grades.

Get CMIT 320 Help

Sources & updates

Published by DomyclassUpdated August 2026