Security control
Also known as: control, safeguard, countermeasure
A measure that lowers risk - technical, like a lock on a system, or organisational, like a rule or training.
Draft - this entry has not been reviewed yet.
Formal
Any technical, organisational, physical or human measure put in place to reduce the likelihood or the impact of a risk. Controls are often sorted by what they do - prevent, detect or correct.
In plain English
Like a smoke alarm, a fire door and a fire drill - three different kinds of measure against the same danger.
In practice
To cut the risk of stolen logins, the IT manager at a small Danish manufacturer turns on MFA (technical), writes a password rule (organisational) and gives staff a short course (human).
Why it matters
Controls are how security decisions become real; each one should answer a named risk, or it only costs money and effort.
Technical deep dive
ISO/IEC 27002:2022 contains 93 controls in four themes: organisational (37), people (8), physical (14) and technological (34). Each control carries five attributes that let an organisation build its own views: control type (#Preventive, #Detective, #Corrective), information security properties (#Confidentiality, #Integrity, #Availability), cybersecurity concepts aligned with the NIST CSF functions (#Identify, #Protect, #Detect, #Respond, #Recover), operational capabilities and security domains. ISO/IEC 27001:2022 Annex A lists the same 93 controls as a reference set; clause 6.1.3 requires the organisation to determine the controls needed to treat its risks, compare them with Annex A so that nothing necessary is overlooked, and produce a Statement of Applicability justifying every inclusion and exclusion. Annex A is therefore a checklist, not a mandatory catalogue.
NIST SP 800-53 Rev. 5 is far more granular: 20 control families, from AC (access control) to SR (supply chain risk management), with base controls, numbered enhancements such as AC-2(1), and organisation-defined parameters. SP 800-53B defines low, moderate and high baselines plus a privacy baseline, and tailoring adjusts them. CIS Controls v8.1 takes a prioritised route instead, with 18 controls broken into safeguards grouped into Implementation Groups IG1 to IG3, where IG1 is described as essential cyber hygiene.
Beyond the preventive, detective and corrective split, many frameworks add deterrent, recovery and compensating controls. A compensating control is an alternative that meets the intent of a requirement when the prescribed control is not feasible, for example network isolation and extra monitoring for a legacy system that cannot be patched; PCI DSS formalises this with documented justification and validation. Controls are also described as manual or automated, and as preventive gates versus detective reviews, which matters for audit sampling.
Auditors test two things: design effectiveness, whether the control as designed would address the risk, and operating effectiveness, whether it actually ran consistently over the period. SOC 2 Type I and Type II reports, and ISAE 3402 and ISAE 3000 assurance reports in Denmark, reflect this distinction. Common failure modes are controls that exist on paper only, controls with no owner or evidence, and controls mapped to no risk, which add cost without reducing risk. A control differs from a policy, which states intent, and from a control objective, which states the outcome; one policy statement is typically realised by several technical and organisational controls, and one control, such as MFA, can support several objectives.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Security control
Relationships
- Kinds
- Access controlEncryptionFirewallAccess managementAsset inventoryBackupChange managementEndpoint detection and response (EDR)HardeningInput validationIntrusion detection system (IDS)Intrusion prevention system (IPS)Multi-factor authenticationOrganisational controlPatch managementPeople controlPhishing simulationPhysical securitySIEMSOARTechnical controlVulnerability assessmentVulnerability scanning
- Requires
- Risk
- Unlocks
- ISO 27001 Annex ACIS ControlsDefence in depthISO 27002Residual riskRisk mitigationRisk treatmentSecurity framework
- Implemented by
- NudgingSecurity awareness
- Don't confuse with
- Security policy
- Mitigates
- VulnerabilityRisk
Sources & further reading
Standards & official texts
- NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations · NIST
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…