Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

5.1.1. Logical Security Controls

ControlFunction
FirewallFilters traffic based on rules (IP, port, protocol, content)
ACLPermit/deny lists based on criteria
IDS/IPSDetect (IDS) or prevent (IPS) intrusions
Content filteringBlock based on content category/type
URL filteringBlock access to specific websites/categories
DLPData Loss Prevention—prevent sensitive data exfiltration
Stateful vs. Stateless Inspection:
  • Stateless: Examines each packet independently
  • Stateful: Tracks connection state; return traffic automatically allowed for established connections
Alvin Varughese
Written byAlvin Varughese
Founder15 professional certifications