Skip to content

Control

What is Control?

A measure (policy, procedure, technical mechanism, or physical safeguard) that modifies risk. Controls can prevent, detect, or correct security incidents.

Information Security

What the standards actually require on control

Requirements naming control across 6 standards, quoted from the control text.

Alternate Communications Paths. Establish [organization-defined] for system operations organizational command and control

NIST800-SC-47 · Alternate Communications Paths. Establish [organization-defined] for system operations organizational command and control
COBIT 201942 controls

Continually monitor and evaluate the control environment and effectiveness of internal controls.

MEA02 · Managed System of Internal Control
IEC 6244340 controls

Physical and logical access controls. Control from IEC 62443 framework, domain: IEC 62443: Access Management.

IEC62443-06 · Physical and logical access controls

The OWASP Top 10 Proactive Controls are used in the development of web applications.

ISM-1849 · The OWASP Top 10 Proactive Controls are used in the development of web applications.

The organization selects and develops control activities that contribute to the mitigation of risks to acceptable levels.

CA-10 · Selects and Develops Control Activities

Endpoints are hardened, deployed with anti-malware, EDR, and managed configurations resistant to tampering.

IS-IV.D.1 · Endpoint Security Controls

Questions people ask about control

What is Control?
A measure (policy, procedure, technical mechanism, or physical safeguard) that modifies risk. Controls can prevent, detect, or correct security incidents.
Why is Control important for compliance?
Control is a key concept in Information Security. Understanding control helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Control?
Key concepts related to Control include Compensating Control. Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Control?
Control appears in the requirement text of NIST SP 800-53 Rev 5, COBIT 2019, IEC 62443, Australian Information Security Manual, COSO Internal Control - Integrated Framework (2013). Across these standards we have identified 233 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Control?
Explore our compliance framework pages to see how control applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Control applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.