Skip to content

Technical Control

What is Technical Control?

A security control implemented through technology such as firewalls, encryption, access controls, and intrusion detection systems.

Information Security

What the standards actually require on technical control

Requirements naming technical control across 6 standards, quoted from the control text.

PCI DSS 4.01 control

When using remote-access technologies, technical controls prevent copy and relocation of PAN for all personnel except those with documented, explicit authorization.

3.4.2 · Technical controls prevent unauthorized PAN copy

Per 10 CFR 73.54 + NRC Regulatory Guide 5.71: defense-in-depth + access control + monitoring + boundary controls + integrity protection.

USNRCCYBER-4 · Defense-in-Depth and Technical Controls
CIS Controls v83 controls

Use technical controls, such as application allowlisting, to ensure that only authorized software can execute or be accessed. Reassess bi-annually, or more frequently.

CIS-2.5 · Allowlist Authorized Software
C5 (Germany)1 control

Deploy risk-derived technical controls that promptly detect and respond to irregular inbound or outbound traffic patterns and distributed denial of service attacks, feeding their output into a SIEM so correlated events can trigger countermeasures.

C5-COS-01 · Technical safeguards

Harden host and guest operating systems, hypervisors and the infrastructure control plane to a documented security baseline enforced by technical controls.

CCM-IVS-04 · OS Hardening and Base Controls

Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;

JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response

Questions people ask about technical control

What is Technical Control?
A security control implemented through technology such as firewalls, encryption, access controls, and intrusion detection systems.
Why is Technical Control important for compliance?
Technical Control is a key concept in Information Security. Understanding technical control helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Technical Control?
Technical Control appears in the requirement text of PCI DSS 4.0, US NRC 10 CFR 73.54 - Cyber Security for Nuclear Power Plants, CIS Controls v8, C5 (Germany), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Technical Control?
Explore our compliance framework pages to see how technical control applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Technical Control applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.