đĽDay 7 of My Security Journey

Student @GKV.FET BTECH CS UG'26 | Python | C | DSA | AWS.
Security Controls & Gap Analysis
Todayâs topic felt like a crash course in âhow organizations actually stay secure.â It wasnât about one tool or one trick, but about the different types of controls and how to figure out where youâre lacking through a gap analysis*.*
đĄď¸ Security Control Categories
I learned that security controls come in four broad flavors. Think of them as different layers of armor for an organization:
Technical Controls â Firewalls, encryption, intrusion detection systems. Basically, the tech side of defense.
Managerial Controls â The admin stuff: policies, governance, and planning. (Not glamorous, but without it everything collapses.)
Operational Controls â Day-to-day human-driven processes like training, monitoring, or incident response.
Physical Controls â The real-world locks, guards, CCTV, and access badges. Because hey, stealing a server physically is still a threat!
đ Security Control Types
Then there are six basic types of security controls (felt like a menu card of defense tools đ´):
Preventive â Stop attacks before they happen.
Deterrent â Make hackers think, âToo much effort, not worth it.â
Detective â Catch malicious activities while or just after they happen.
Corrective â Fix things and restore normal operations.
Compensating â Backup measures when the main control isnât possible.
Directive â Policies, standards, and documentation that guide user behavior.
Reading this gave me a new appreciation of how layered and diverse cybersecurity really isâitâs not just about blocking, itâs about managing risk from every angle.
đ Gap Analysis â Finding the Weak Spots

The second half of my study was about Gap Analysisâbasically asking:
đ Where are we today? Where do we want to be? And whatâs missing in between?
Steps I learned:
Define the scope.
Gather data about the current state.
Identify gaps.
Make a plan to fix them.
There are two main types:
Technical Gap Analysis â Focuses on tech infrastructure.
Business Gap Analysis â Focuses on processes and operations.
The cool part? Organizations use something called a Plan of Action and Milestones (POA&M) to address these gapsâlike a roadmap with deadlines and resources allocated.
đ My Reflection on Day 7
What stood out to me today is that cybersecurity is never âdone.â Youâre always checking, adjusting, and improving. Security controls give you the tools, but gap analysis makes sure youâre actually using them effectively.
Itâs like going to the gymâyou can have the best equipment (controls), but without a proper workout plan (gap analysis + POA&M), you wonât make progress.




