What is a security control?
A security control is a safeguard or countermeasure, technical, administrative, or physical, that reduces information security risk by preventing, detecting, or correcting a threat.
Definition
A security control is a specific safeguard or countermeasure put in place to reduce information security risk. Controls are commonly categorized by function (preventive, detective, corrective) and by type (technical, administrative, and physical).
Background
Every compliance framework is, at heart, a set of expected security controls. SOC 2 has its Trust Services Criteria, ISO 27001 has its Annex A controls, and frameworks like NIST and CIS publish their own control sets. Because the same underlying safeguard (say, multi-factor authentication) satisfies requirements in many frameworks, a control can be mapped, or crosswalked, to several standards at once.
Why it matters
Controls are the unit of work in a compliance program: you implement them, prove they operate with evidence, and map them to the frameworks you need. Thinking in controls rather than in separate frameworks is what lets you collect evidence once and satisfy many standards.
Step by step
- Identify the risk the control is meant to reduce.
- Choose the control type that fits (preventive, detective, or corrective).
- Assign an owner and implement it.
- Collect evidence that the control operates, not just that it exists.
- Map the control to the framework requirements it satisfies.
- Review it on a cadence and after significant change.
Examples
- Preventive technical control: enforcing multi-factor authentication on all administrative access.
- Detective technical control: centralized logging and alerting on suspicious activity.
- Administrative control: an access-review process that removes access when someone changes roles.
Common mistakes
- Documenting a control on paper without evidence that it actually operates.
- Duplicating control work per framework instead of mapping one control to many.
- Owning controls nowhere, so nobody maintains them between audits.
FAQ
What are the main types of security controls?
By function: preventive (stop an incident), detective (spot one), and corrective (fix one). By type: technical (in systems), administrative (policies and processes), and physical (facilities). Most programs use a mix.
Can one control satisfy multiple frameworks?
Yes. Many controls map to several frameworks at once. A crosswalk records those relationships so evidence collected once can count toward SOC 2, ISO 27001, and others.
Do this in Keel, not a spreadsheet
Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free