Preventive vs detective controls
Preventive controls block a non-compliant change before it is made, and detective controls expose a non-compliant state after it appears. In infrastructure as code, prevention runs before apply, while detection relies on scans and runtime monitoring.
Comparison
| Preventive | Detective | |
|---|---|---|
| When it acts | Prior to planning or applying resources | Once code exists or resources are live |
| Terraform examples | Module defaults and input validation; a policy that refuses a plan | Checkov or Trivy scans; AWS Config rules; Security Hub findings |
| Result of a violation | The proposed change is blocked | A finding someone has to triage and fix |
| What it can see | Only the path it protects | Anything the scanner or monitor can read, including drift and console edits |
| Typical audit evidence | Module source, plan output | Scan reports, configuration history |
Why teams need both
On the path it protects, a preventive control takes away the opportunity for a misconfiguration, so there is less to fix and account for; the audit evidence guide shows how each type appears during an audit. That protection stops at the path boundary. A resource made through the console, or one built from a module outside the catalog, never crosses it, and importing an existing resource does not prove it was compliant before import. Detective tooling supplies an independent check and catches those cases.
How compliance.tf applies it
compliance.tf modules act as preventive controls. The module carries the control as defaults and input validation, so a non-compliant value fails at terraform plan:
│ Error: Invalid value for variable
│
│ s3_bucket_logging_enabled: logging.target_bucket must be set
│ to enable S3 bucket access logging.
│
│ Frameworks requiring this control:
│ SOC 2, CIS AWS v1.4.0 (3.6), PCI DSS v4.0 (10.2.1)compliance.tf does not detect drift and works only while infrastructure as code is being authored. Run a scanner in CI and keep runtime monitoring in AWS, so each layer verifies the other.