UNIVERSITY OF MARYLAND GLOBAL CAMPUS • UMGC • CMIT 320
How should a security control be matched to a threat?
Match a security control to a threat by identifying the protected asset, security objective, high-level threat mechanism, and vulnerability or exposure first. Then state the control objective and show exactly which part of that path the safeguard prevents, reduces, detects, contains, corrects, or compensates for. Evaluate coverage, timing, dependencies, limitations, and evidence of effectiveness. A familiar control name is not enough. The recommendation is defensible only when the control changes the stated scenario, its tradeoffs are explicit, and the remaining residual risk is monitored.
Decision resource
Control-to-Threat Fit Checklist
An eight-check review of objective fit, path fit, coverage, timing, feasibility, dependencies, limitations, and evidence.
Step 1
- check
- Objective and path
- question
- Which security objective and part of the threat path change?
- warning signal
- Only a broad threat and product name appear
Step 2
- check
- Coverage and timing
- question
- What is covered, and when does the response act?
- warning signal
- Important users, assets, states, or moments are missing
Step 3
- check
- Feasibility and dependencies
- question
- Can the control be operated under stated assumptions?
- warning signal
- Ownership, data, skill, or integration is assumed
Step 4
- check
- Limitations and proof
- question
- What remains, and which evidence shows effectiveness?
- warning signal
- The response claims elimination or measures only deployment
Trace the threat path before naming a safeguard
Begin with a fictional protected asset and the confidentiality, integrity, availability, authenticity, or accountability objective that matters. Describe a high-level mechanism of harm and the exposure that makes it plausible. Keep the two separate. The threat may be unauthorized change; the exposure may be inconsistent approval. Ask where the path can be interrupted or observed. This creates the control objective. Without that trace, a recommendation such as use access control is too broad to evaluate. The student should be able to point to the exact relationship the safeguard changes without adding operational attack detail.
Use the Control-to-Threat Fit Checklist
Check objective fit, path fit, coverage, timing, feasibility, dependencies, limitations, and proof. Objective fit asks whether the safeguard preserves the security property. Path fit asks whether it affects the mechanism or exposure. Coverage asks which users, assets, and operating states are included. Timing asks whether it acts early enough. Feasibility covers ownership, skill, cost, and maintenance. Dependencies reveal shared failure. Limitations explain what remains. Proof identifies an indicator or test. A weak answer skips from the threat label to a product. A strong answer makes every link visible.
Fictional example: an equipment-reservation service
A fictional community workshop wants reliable equipment reservations. The objective is record integrity. The bounded threat mechanism is inappropriate schedule change, and the exposure is excessive permissions after volunteers change roles. A role-review process addresses ownership; a technical authorization boundary constrains changes; exception monitoring provides detection. The controls fit because they change the identified exposure and mechanism. They do not eliminate approved-user error, delayed role updates, or incomplete monitoring. Those limitations become residual risk and monitoring questions. The example requires no instructions for bypassing the service.
Compare the primary control with a complementary layer
A preventive safeguard may reduce opportunity while a detective layer reveals exceptions. A corrective process may restore trusted information after an error. A compensating process may cover a temporary constraint. Compare at least one alternative by the same checklist. Explain why it is a companion, substitute, or poor fit. More layers are not automatically better; duplicated dependencies or unclear ownership can add complexity without meaningful coverage. The chosen combination should be proportionate to the fictional consequence and supported by evidence.
End with residual risk and evidence
State what remains because of control limitations, human error, changing conditions, or uncertainty. Name the owner who would decide whether that risk is acceptable and the evidence that triggers reassessment. Measures should show more than implementation. Review accuracy, exception age, response timing, coverage, or restoration testing may be more informative than the number of installed safeguards. Do not call the remaining risk zero. A transparent residual statement makes the control recommendation credible.
Write one control-fit sentence before the recommendation
Use a sentence that names the safeguard function, the exact part of the bounded path it changes, the expected evidence, and the main limitation. This forces the relationship into view before supporting detail is added. Then compare one plausible companion or alternative and explain whether it closes a different gap or repeats the same dependency. The concise sentence is not the whole answer, but it is a strong diagnostic for vague fit.
Keep the work defensive and learner-owned
Use the checklist to review a control argument you write under current classroom instructions. Domyclass can explain a mismatch or missing limitation. It will not choose controls for a live target, provide exploitation steps, create a completed security plan, or supply certification answers. The reasoning and final submitted language remain yours.
Related CMIT 320 resources
Get Help With CMIT 320 Network Security at University of Maryland Global Campus
Get targeted CMIT 320 help and improve your grades.
Get CMIT 320 HelpSources & updates
- University of Maryland Global Campus: Course Information: Network Security (CMIT 320)
- University of Maryland Global Campus: Online Cybersecurity Technology Bachelor’s Degree
- University of Maryland Global Campus: Online Computer Networking & Cybersecurity Undergraduate Certificate
- National Institute of Standards and Technology: CSRC Glossary: Residual Risk
- National Institute of Standards and Technology: CSRC Glossary: Defense in Depth
Published by Domyclass • Updated August 2026