Security Controls
What is Security Controls?
Safeguards or countermeasures designed to protect the confidentiality, integrity, and availability of information systems and data. Controls can be technical (encryption, firewalls), administrative (policies, training), or physical (locks, cameras).
Terms that appear alongside security controls
Each of these is named in at least one of the same controls as security controls. The number is how many controls name both.
- information security 16 shared controls
- nist 15 shared controls
- cybersecurity 15 shared controls
- audit 14 shared controls
- access control 12 shared controls
- encryption 11 shared controls
- integrity 11 shared controls
- compliance 11 shared controls
Frameworks that govern security controls
What the standards actually require on security controls
Requirements naming security controls across 6 standards, quoted from the control text.
Endpoints are hardened, deployed with anti-malware, EDR, and managed configurations resistant to tampering.
IS-IV.D.1 · Endpoint Security Controls →Periodically assess the security controls in organizational information systems to determine if the controls are effective in their application.
SP800-171-3.12.1 · Periodically assess security controls →Implement and maintain the security controls of RG 5.71 Appendix B and C or equivalent (NEI 08 09 Appendices D and E) for each Critical Digital Asset, addressing technical, management, and operational controls, with documented basis for any alternative measure...
NRC-73.54(b)(3) · Application of Security Controls to CDAs →Security controls are implemented on any computing devices that connect to both untrusted networks and the CDE to prevent threats entering via these devices.
1.5.1 · Security controls on dual-connected computing devices →Internal audit activities must include review of the design and operating effectiveness of information security controls, including those maintained by related parties and third parties.
CPS234-25 · Internal Audit Review of Information Security Controls →Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined]
NIST800-SC-38 · Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined] →Questions people ask about security controls
What is Security Controls?
Why is Security Controls important for compliance?
Which compliance frameworks address Security Controls?
Where can I learn more about Security Controls?
See how Security Controls applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.