A security control is an action or safeguard an organization uses to reduce a defined risk.
Controls can be:
- Technical: MFA, encryption, logging, endpoint protection, or backups
- Process-based: Access reviews, incident response, change approval, or vendor assessment
- People-based: Training, role assignments, approvals, and management review
A control is stronger when the organization can explain its purpose, owner, implementation, evidence, review frequency, and relationship to risk or a framework requirement. A policy may describe the expected control, but the control is only useful when it operates in practice.
Framework-Pro helps teams move from framework selection to relevant controls, tailored policies, and evidence placeholders. See why choosing the right security controls matters.
