Intrusion detection systems, vulnerability scans, penetration tests, and logs are examples of controls designed to detect potential problems and security incidents. Incident response teams, business continuity management, and patch
management systems are commonly used examples of controls designed to correct problems that have been
identified.