Security Control
A security control is a safeguard or measure put in place to protect information systems, networks, and data from threats. Its purpose is typically to protect the confidentiality, integrity, and availability of information and the systems that handle it. Controls can act before, during, or after an event, and no single control should be assumed to eliminate risk entirely.
A security control is a safeguard or countermeasure prescribed for an information system or an organization to protect the confidentiality, integrity, and availability of the system and its information. In practice, controls are selected, deployed, configured, monitored, and improved across a lifecycle, and are commonly classified by function, such as corrective controls that operate after an event has been detected and may reduce or reverse its impact. Frameworks such as the NIST security control catalogs and the CIS Critical Security Controls provide structured sets of controls; applicability and specific control selection vary by organization, system context, threat environment, and applicable regulatory or contractual requirements. Security controls modify risk rather than remove it, so residual risk typically remains and should be assessed against the organization's risk appetite and tolerance.
Why it matters
Security controls are the practical mechanisms through which an organization translates its risk posture into action, protecting the confidentiality, integrity, and availability of its information systems, networks, and data. Without deliberate safeguards, the exposure created by threats to systems would remain unmitigated. It is important to recognize, however, that controls modify risk rather than remove it; residual risk typically remains even after controls are deployed, and that residual risk should be assessed against the organization's risk appetite and tolerance.
Who it's relevant to
Inside Security Control
Common questions
Answers to the questions practitioners most commonly ask about Security Control.

