As mentioned in the previous section, security professionals spend a large amount of their
time developing ways to mitigate risks facing an organization’s information assets. The methods
they develop to reduce risk are known as security controls and are grouped into three
categories: technical controls, operational controls, and management controls. A balanced
approach to information security combines controls from each of these categories to mitigate
a wide variety of risks.