Skip to content

Control Objective

What is Control Objective?

A statement of the desired result or purpose to be achieved by implementing a control. Control objectives define what the organisation wants to achieve through its control activities and provide the basis for control design and assessment.

Governance

What the standards actually require on control objective

Requirements naming control objective across 6 standards, quoted from the control text.

Management identifies control objectives and states controls suitably designed to achieve them.

ISAE3402-8 · Control Objectives

Derive control objectives from compliance, regulatory and business requirements, document them, and trace each to implemented AWS controls with measurable validation.

SEC01-BP03 · Identify and validate control objectives

The organization internally communicates information including internal control objectives. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Information and Communication.

COSO-IC-IC-14 · The organization internally communicates information including internal control objectives

The provider's risk treatment decisions for the assessed service are aligned with the CCM control objectives, with residual risks documented and accepted at an appropriate level.

STAR-RISK-01 · Risk treatment alignment with CCM

Every ISO/IEC 27002 guideline that speaks of information security must be read as extending to the protection of privacy affected by the processing of personally identifiable information, and every control objective and control must be considered against priva...

iso-27701-2019::6.1 · General

Apply NIST SP 800-146 Section 9.7 (Auditing and Accountability) + Section 9.8 (Cost Management) + Section 9.9 (Lessons Learned). Auditing and accountability require (a) cloud audit log ingestion into the enterprise SIEM, (b) cloud provider audit report (SOC 2...

NISTSP146-8 · Cloud Auditing, Accountability, Cost Management, and Lessons Learned

Questions people ask about control objective

What is Control Objective?
A statement of the desired result or purpose to be achieved by implementing a control. Control objectives define what the organisation wants to achieve through its control activities and provide the basis for control design and assessment.
Why is Control Objective important for compliance?
Control Objective is a key concept in Governance. Understanding control objective helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Control Objective?
Control Objective appears in the requirement text of ISAE 3402 - Assurance Reports on Controls at a Service Organisation, AWS Well-Architected Security Pillar, COSO Internal Control - Integrated Framework (2013), CSA STAR (Security, Trust, Assurance, and Risk), ISO 27701:2019. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Control Objective?
Explore our compliance framework pages to see how control objective applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Control Objective applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.