Security Control
A security control is a safeguard or countermeasure put in place to protect information, systems, or physical property from security threats. Controls may work by avoiding, detecting, counteracting, or reducing the impact of a security risk. Examples range from technical measures to physical and administrative practices.
A security control is a safeguard or countermeasure prescribed for an information system or an organization to protect the confidentiality, integrity, and availability of the system and its information. Controls are commonly classified by function, including preventive, detective, and corrective types; for example, a corrective control operates after an event has been detected and may reverse or limit its impact. In practice, controls are selected to avoid, detect, counteract, or minimize security risks and are typically drawn from established control catalogs and baselines. This entry addresses the concept of security controls generally and does not cover specific implementation, tooling, or the selection of a particular control framework.
Why it matters
Security controls are the practical mechanisms through which an organization translates its risk decisions into protection for information, systems, and physical property. Without controls, risk assessment remains theoretical; controls are the means by which identified risks are avoided, detected, counteracted, or reduced in impact. In governance and risk terms, they represent the treatment applied to threats against the confidentiality, integrity, and availability of information and systems.
The way controls are classified matters for how an organization designs its overall defenses. Preventive controls aim to stop an event before it occurs, detective controls identify that an event is taking place or has taken place, and corrective controls operate after an event has been detected and may reverse or limit its impact. Relying on any single type tends to leave gaps, so organizations commonly combine control functions so that a failure or bypass of one is caught or remediated by another.
Controls also provide the evidentiary basis for demonstrating that risk is being managed. Established catalogs and baselines, such as those maintained by NIST and the CIS Controls published by the Center for Internet Security, give organizations a structured starting point for selecting and describing safeguards. It should be noted that a control's presence does not by itself guarantee a risk is fully addressed; its effectiveness depends on correct selection, implementation, and operation, none of which this entry evaluates.
Who it's relevant to
Inside Security Control
Common questions
Answers to the questions practitioners most commonly ask about Security Control.
