A Security Control constitutes a measure applied to manage a security risk.
A Security Control addresses one or more security objectives, including Confidentiality, Integrity, availability, Authentication, authorization, accountability, and non-repudiation.
Security Controls include administrative, managerial, operational, physical, procedural, and technical measures. A policy, assigned responsibility, approval procedure, facility restriction, encryption mechanism, Access Control, monitoring process, or audit record serves as a Security Control when it manages an identified security risk.
A Security Control remains distinct from a security objective. A security objective identifies a desired security outcome. A Security Control provides a measure used to achieve or preserve that outcome.
measure applied to manage a security risk
Adapted from ISO/IEC 27000, *Information security, cybersecurity and privacy protection — Vocabulary*.
A Security Control has an identified purpose, scope, responsible authority, implementation method, operating conditions, and assessment criteria.
An organization selects and applies a Security Control according to the applicable risks, requirements, policies, legal obligations, regulatory obligations, and operating environment.
A Security Control includes preventive, deterrent, detective, corrective, recovery, or compensating measures.
Control assessment determines whether a Security Control exists, operates as intended, and produces the required security outcome.
The presence of a Security Control does not independently establish that the associated risk has been eliminated.
A Test Environment applies encryption, Access Control, credential rotation, audit logging, and protected secret storage as Security Controls for Sensitive Configuration Values.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.