Types of control
By purpose: preventive controls stop incidents, such as MFA or a firewall; detective controls reveal them, such as alerts or log review; corrective controls limit the damage and restore operations, such as backups and incident response. By nature: organisational, people, physical and technological, the four themes used in Annex A of ISO 27001, which lists 93 controls.
Design and operation
A control can be well designed on paper and still fail in practice. Auditors check both: that the control exists and is appropriate for the risk, and that it actually operates over time. A SOC 2 Type II report, for example, tests whether controls operated effectively across a period of several months.
Choosing controls
Controls should follow from the risk assessment, not from a checklist. The risk treatment plan records which ones are selected, and the Statement of Applicability explains which Annex A controls apply and why. Many frameworks overlap, so a single control, such as MFA, often satisfies requirements in ISO 27001, the ENS, SOC 2 and NIS2 at once.
Owners and evidence
Each control needs an owner, a description of how it works, a frequency and the evidence it produces. Controls without an owner tend to stop operating unnoticed, which is how many audit findings arise.




