These examples show why a flat category list is not enough. The classification should follow the control’s actual design and operating context.
Control
Lifecycle
Purpose
Mechanism
Evidence
Phishing-resistant MFA for administrators
Protect; Govern for policy and exception oversight.
Primarily preventive; detective when risky sign-ins generate actionable alerts.
Technical, supported by administrative enrollment and exception procedures.
Policy assignment, authentication-method coverage, admin-role list, sign-in test, exception register.
Managed endpoint detection and response
Protect, Detect, and Respond.
Preventive, detective, and corrective through isolation or remediation.
Technical, supported by operational triage and escalation procedures.
Coverage report, policy export, health status, controlled alert, ticket timestamps, containment test.
Restricted server-room access
Protect and Detect; Govern for access policy and review.
Preventive, deterrent, and detective.
Physical, technical, and administrative.
Authorized-user list, badge events, visitor log, alarm test, quarterly access review, termination test.
Isolated backup with restore testing
Protect and Recover; Govern for recovery objectives and accountability.
Recovery and corrective; preventive against permanent data loss.
Technical and administrative, with physical controls when removable media or alternate sites are used.
Job history, protected-admin settings, immutability or isolation proof, restore result, elapsed time, integrity validation.
Legacy device segmentation
Compensating and preventive, with detective monitoring.
Technical, governed by an approved risk exception and replacement plan.
Network rule, exposure test, monitoring coverage, risk approval, expiry date, replacement milestone.