GlossaryGlossary

Control applicability

Control applicability is the reasoned decision about whether a security control is relevant to an organization's scope, risks, requirements, or operating model.

August 31, 2026Updated August 2026
Security controlsISO 27001Risk management

Control applicability is the decision about whether a control belongs in the organization’s security program and why.

The decision should consider:

  • Scope and critical business services
  • Data, systems, identities, and suppliers
  • Threats and vulnerabilities
  • Legal, regulatory, contractual, or customer expectations
  • Existing safeguards and planned treatment

Applicable does not mean implemented. A control can be relevant but still in progress, partially implemented, or missing evidence. Keeping applicability, implementation status, and evidence status separate makes reporting more honest and useful.

See what control applicability really means in ISO 27001.