Skip to content
atlas

Don't confuse these

Security control vs Security policy

Why they differ

A policy says what should be achieved; a control is the concrete measure that achieves it.

Security control

Fundamentals

A measure that lowers risk - technical, like a lock on a system, or organisational, like a rule or training.

Formal

Any technical, organisational, physical or human measure put in place to reduce the likelihood or the impact of a risk. Controls are often sorted by what they do - prevent, detect or correct.

In plain English

Like a smoke alarm, a fire door and a fire drill - three different kinds of measure against the same danger.

In practice

To cut the risk of stolen logins, the IT manager at a small Danish manufacturer turns on MFA (technical), writes a password rule (organisational) and gives staff a short course (human).

Why it matters

Controls are how security decisions become real; each one should answer a named risk, or it only costs money and effort.

Security policy

Fundamentals

A document that sets out an organisation's goals, responsibilities and principles for information security.

Formal

A leadership-approved statement of the organisation's intent for information security - its goals, who is responsible for what, and the rules everyone must follow. It is reviewed at set times and backed by more detailed rules for specific topics.

In plain English

Like the house rules on a fridge - short, agreed by the grown-ups, and meant to settle arguments before they start.

In practice

A new case worker at a Danish municipality reads and accepts the security policy on day one; among other things it says that work files may only be stored in approved places, never on a private cloud account.

Why it matters

It turns leadership's intent into something written and shared, which every later rule, control and audit can point back to.

Shared connections

Atlas is in beta.