Show pageOld revisionsBacklinksAdd to bookExport to PDFODT exportBack to top This page is read only. You can view the source, but not change it. Ask your administrator if you think this is wrong. ====== Security Control ====== [[dido:99_annexes:annex-b-terms-and-definitions:start|Go up to Terms and Definitions]] ===== Discussion ===== A Security Control constitutes a measure applied to manage a security risk. A Security Control addresses one or more security objectives, including [[dido:99_annexes:annex-b-terms-and-definitions:c:confidentiality|Confidentiality]], [[dido:99_annexes:annex-b-terms-and-definitions:i:integrity|Integrity]], availability, [[dido:99_annexes:annex-b-terms-and-definitions:a:authentication|Authentication]], authorization, accountability, and non-repudiation. Security Controls include administrative, managerial, operational, physical, procedural, and technical measures. A policy, assigned responsibility, approval procedure, facility restriction, encryption mechanism, [[dido:99_annexes:annex-b-terms-and-definitions:a:access_control|Access Control]], monitoring process, or audit record serves as a Security Control when it manages an identified security risk. A Security Control remains distinct from a security objective. A security objective identifies a desired security outcome. A Security Control provides a measure used to achieve or preserve that outcome. ===== Definition ===== //measure applied to manage a security risk// ===== Source ===== Adapted from ISO/IEC 27000, *Information security, cybersecurity and privacy protection — Vocabulary*. ===== Note ===== A Security Control has an identified purpose, scope, responsible authority, implementation method, operating conditions, and assessment criteria. An organization selects and applies a Security Control according to the applicable risks, requirements, policies, legal obligations, regulatory obligations, and operating environment. A Security Control includes preventive, deterrent, detective, corrective, recovery, or compensating measures. Control assessment determines whether a Security Control exists, operates as intended, and produces the required security outcome. The presence of a Security Control does not independently establish that the associated risk has been eliminated. ===== Example ===== A Test Environment applies encryption, Access Control, credential rotation, audit logging, and protected secret storage as Security Controls for [[dido:99_annexes:annex-b-terms-and-definitions:s:sensitive_configuration_value|Sensitive Configuration Values]]. ---- <WRAP centeralign> © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. </WRAP> dido/99_annexes/annex-b-terms-and-definitions/s/security_control.txt Last modified: 2026/08/08 13:29by nick_dido