GlossaryCompliance operations

Security control

Short answer

A security control is any measure that reduces an information security risk: a policy, a process, a technical setting or a physical barrier. Examples include MFA, backups, access reviews and visitor registers. Standards such as ISO 27001, the ENS and SOC 2 are largely built around sets of controls.

Types of control

By purpose: preventive controls stop incidents, such as MFA or a firewall; detective controls reveal them, such as alerts or log review; corrective controls limit the damage and restore operations, such as backups and incident response. By nature: organisational, people, physical and technological, the four themes used in Annex A of ISO 27001, which lists 93 controls.

Design and operation

A control can be well designed on paper and still fail in practice. Auditors check both: that the control exists and is appropriate for the risk, and that it actually operates over time. A SOC 2 Type II report, for example, tests whether controls operated effectively across a period of several months.

Choosing controls

Controls should follow from the risk assessment, not from a checklist. The risk treatment plan records which ones are selected, and the Statement of Applicability explains which Annex A controls apply and why. Many frameworks overlap, so a single control, such as MFA, often satisfies requirements in ISO 27001, the ENS, SOC 2 and NIS2 at once.

Owners and evidence

Each control needs an owner, a description of how it works, a frequency and the evidence it produces. Controls without an owner tend to stop operating unnoticed, which is how many audit findings arise.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub