4Security controls
- 4.1Human and physical controls
Covers organizational deterrence measures based on the internal-fraud-prevention guideline, security education via targeted-email drills and red team exercises, the need-to-know (least privilege) principle and privileged access management, log management, entry/exit control including anti-passback and interlock mechanisms, clear desk / clear screen policy, and RASIS, the metric set for system reliability.
- 4.2Malware and unauthorized-access countermeasures
Covers malware detection techniques—pattern matching, the behavior method, the heuristic method, dynamic analysis, and static analysis—the concepts of entry-point (ingress) controls, exit-point (egress) controls, and defense in depth, quarantine networks for isolating infected endpoints, the DMZ, vulnerability management (patching), hardening, and secret sharing for splitting a key across multiple holders.
- 4.3Security products
Organizes the diverse landscape of security products—firewall, IDS/IPS (signature-based/anomaly-based), WAF, RASP, UTM, DLP, SIEM, EDR, CASB, SASE, MDM, and IdP—by what each protects and how it detects threats, along with the false positive/false negative trade-off.
- 4.4Zero trust and new defense approaches
Covers zero trust architecture, which discards the assumption that "inside the perimeter is trustworthy" (verify everything, microsegmentation), threat intelligence (OSINT) for gathering and analyzing attacker trends, digital forensics, which emphasizes evidence preservation and integrity, IoT security and operational technology (OT) security, and hardware-level defenses via secure boot, TPM, and SED.

