Skip to content

Security Controls

What is Security Controls?

Safeguards or countermeasures designed to protect the confidentiality, integrity, and availability of information systems and data. Controls can be technical (encryption, firewalls), administrative (policies, training), or physical (locks, cameras).

Information Security

Each of these is named in at least one of the same controls as security controls. The number is how many controls name both.

What the standards actually require on security controls

Requirements naming security controls across 6 standards, quoted from the control text.

Endpoints are hardened, deployed with anti-malware, EDR, and managed configurations resistant to tampering.

IS-IV.D.1 · Endpoint Security Controls
NIST SP 800-1713 controls

Periodically assess the security controls in organizational information systems to determine if the controls are effective in their application.

SP800-171-3.12.1 · Periodically assess security controls

Implement and maintain the security controls of RG 5.71 Appendix B and C or equivalent (NEI 08 09 Appendices D and E) for each Critical Digital Asset, addressing technical, management, and operational controls, with documented basis for any alternative measure...

NRC-73.54(b)(3) · Application of Security Controls to CDAs
PCI DSS 4.03 controls

Security controls are implemented on any computing devices that connect to both untrusted networks and the CDE to prevent threats entering via these devices.

1.5.1 · Security controls on dual-connected computing devices
APRA CPS 2342 controls

Internal audit activities must include review of the design and operating effectiveness of information security controls, including those maintained by related parties and third parties.

CPS234-25 · Internal Audit Review of Information Security Controls

Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined]

NIST800-SC-38 · Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined]

Questions people ask about security controls

What is Security Controls?
Safeguards or countermeasures designed to protect the confidentiality, integrity, and availability of information systems and data. Controls can be technical (encryption, firewalls), administrative (policies, training), or physical (locks, cameras).
Why is Security Controls important for compliance?
Security Controls is a key concept in Information Security. Understanding security controls helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Security Controls?
Security Controls appears in the requirement text of FFIEC IT Examination Handbook, NIST SP 800-171, NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity, PCI DSS 4.0, APRA CPS 234. Across these standards we have identified 16 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Security Controls?
Explore our compliance framework pages to see how security controls applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Security Controls applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.