Identifying Control Failures

Identifying Control Failures

Understanding which controls failed helps prioritize improvements:

Control Failure Analysis Matrix:

Control LayerExpected FunctionActual PerformanceFailure Mode
Email GatewayBlock malicious attachmentsAllowed throughSignature not available
User TrainingRecognize phishingUser clicked linkTraining was 18 months old
Endpoint ProtectionDetect malware executionNo alert generatedDefinition outdated
Network MonitoringDetect C2 trafficTraffic observed but not alertedSIEM rule too narrow
Backup SystemEnable recoveryBackups encryptedSame credentials used
Incident ResponseRapid containment6-hour responseOn-call process unclear