Control
What is Control?
A measure (policy, procedure, technical mechanism, or physical safeguard) that modifies risk. Controls can prevent, detect, or correct security incidents.
Related terms
Frameworks that govern control
What the standards actually require on control
Requirements naming control across 6 standards, quoted from the control text.
Alternate Communications Paths. Establish [organization-defined] for system operations organizational command and control
NIST800-SC-47 · Alternate Communications Paths. Establish [organization-defined] for system operations organizational command and control →Continually monitor and evaluate the control environment and effectiveness of internal controls.
MEA02 · Managed System of Internal Control →Physical and logical access controls. Control from IEC 62443 framework, domain: IEC 62443: Access Management.
IEC62443-06 · Physical and logical access controls →The OWASP Top 10 Proactive Controls are used in the development of web applications.
ISM-1849 · The OWASP Top 10 Proactive Controls are used in the development of web applications. →The organization selects and develops control activities that contribute to the mitigation of risks to acceptable levels.
CA-10 · Selects and Develops Control Activities →Endpoints are hardened, deployed with anti-malware, EDR, and managed configurations resistant to tampering.
IS-IV.D.1 · Endpoint Security Controls →Questions people ask about control
What is Control?
Why is Control important for compliance?
What concepts are related to Control?
Which compliance frameworks address Control?
Where can I learn more about Control?
See how Control applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.