Skip to content
atlas

Security control

Also known as: control, safeguard, countermeasure

A measure that lowers risk - technical, like a lock on a system, or organisational, like a rule or training.

Draft - this entry has not been reviewed yet.

Formal

Any technical, organisational, physical or human measure put in place to reduce the likelihood or the impact of a risk. Controls are often sorted by what they do - prevent, detect or correct.

In plain English

Like a smoke alarm, a fire door and a fire drill - three different kinds of measure against the same danger.

In practice

To cut the risk of stolen logins, the IT manager at a small Danish manufacturer turns on MFA (technical), writes a password rule (organisational) and gives staff a short course (human).

Why it matters

Controls are how security decisions become real; each one should answer a named risk, or it only costs money and effort.

Technical deep dive

ISO/IEC 27002:2022 contains 93 controls in four themes: organisational (37), people (8), physical (14) and technological (34). Each control carries five attributes that let an organisation build its own views: control type (#Preventive, #Detective, #Corrective), information security properties (#Confidentiality, #Integrity, #Availability), cybersecurity concepts aligned with the NIST CSF functions (#Identify, #Protect, #Detect, #Respond, #Recover), operational capabilities and security domains. ISO/IEC 27001:2022 Annex A lists the same 93 controls as a reference set; clause 6.1.3 requires the organisation to determine the controls needed to treat its risks, compare them with Annex A so that nothing necessary is overlooked, and produce a Statement of Applicability justifying every inclusion and exclusion. Annex A is therefore a checklist, not a mandatory catalogue.

NIST SP 800-53 Rev. 5 is far more granular: 20 control families, from AC (access control) to SR (supply chain risk management), with base controls, numbered enhancements such as AC-2(1), and organisation-defined parameters. SP 800-53B defines low, moderate and high baselines plus a privacy baseline, and tailoring adjusts them. CIS Controls v8.1 takes a prioritised route instead, with 18 controls broken into safeguards grouped into Implementation Groups IG1 to IG3, where IG1 is described as essential cyber hygiene.

Beyond the preventive, detective and corrective split, many frameworks add deterrent, recovery and compensating controls. A compensating control is an alternative that meets the intent of a requirement when the prescribed control is not feasible, for example network isolation and extra monitoring for a legacy system that cannot be patched; PCI DSS formalises this with documented justification and validation. Controls are also described as manual or automated, and as preventive gates versus detective reviews, which matters for audit sampling.

Auditors test two things: design effectiveness, whether the control as designed would address the risk, and operating effectiveness, whether it actually ran consistently over the period. SOC 2 Type I and Type II reports, and ISAE 3402 and ISAE 3000 assurance reports in Denmark, reflect this distinction. Common failure modes are controls that exist on paper only, controls with no owner or evidence, and controls mapped to no risk, which add cost without reducing risk. A control differs from a policy, which states intent, and from a control objective, which states the outcome; one policy statement is typically realised by several technical and organisational controls, and one control, such as MFA, can support several objectives.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Threat
  3. →Asset
  4. →Vulnerability
  5. →Impact
  6. →Likelihood
  7. →Risk
  8. →Security control

Relationships

Requires
Risk
Don't confuse with
Security policy

Sources & further reading

Standards & official texts

  • NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations · NIST

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.