GlossaryGlossary

Security control

A security control is a safeguard, process, or responsibility used to reduce risk and protect systems, data, people, or business operations.

August 31, 2026Updated August 2026
Security controlsFramework readinessGRC

A security control is an action or safeguard an organization uses to reduce a defined risk.

Controls can be:

  • Technical: MFA, encryption, logging, endpoint protection, or backups
  • Process-based: Access reviews, incident response, change approval, or vendor assessment
  • People-based: Training, role assignments, approvals, and management review

A control is stronger when the organization can explain its purpose, owner, implementation, evidence, review frequency, and relationship to risk or a framework requirement. A policy may describe the expected control, but the control is only useful when it operates in practice.

Framework-Pro helps teams move from framework selection to relevant controls, tailored policies, and evidence placeholders. See why choosing the right security controls matters.