Security controls are the measures, safeguards, and procedures organizations put in place to reduce cybersecurity risk, and they can be understood through three distinct definitions depending on the context. They are also organized by category and type to address different aspects of an organization's security posture.
Security Controls
One of the things that we want to implement on our network are controls, controls that help us implement security. But what is a control? The first thing that you have to understand with controls is that different people have different definitions and different viewpoints on what a control is. I've really rendered this down into three different definitions for it. Number one, anything that you do, anything that you implement, is a control that helps mitigate risk. Number two, it is pretty much the same thing as a standard. And number three, it's a standard, but it takes it to another level. Let's talk about those different definitions.
Here's definition number one, or perspective number one on this, and this is what you'll find in a certification like a Security+, or NIST defines it this way: it's any measure or safeguard you put into place to help cybersecurity. So it's the actions you take, it's the devices you implement, it's the procedures that you implement. Anything that you do is a control that you're putting in place to mitigate risk.
I've also often heard of controls and standards being used interchangeably. Something like NIST 800-53 is one example of this, where I've seen controls being used in place of what a standard is. It just sets up what the expectations are and lays out the standards that you are going to meet. So that's number two.
Definition number three is something that I see when it comes more towards compliance. For instance, this is like SOC 2: they have controls that you have in place, and what is it? It's some sort of measurable outcome. It's not just a standard, but you have to turn something over to prove that you've met that standard. So it's taking a standard to the next level by proving that you actually are doing it.
There are several different control categories, so we can categorize the different controls that we're putting into place.
Number one, we could be having physical controls. That's the fences and the doors and the different physical aspects that we're putting into place to protect our technology.
Then there's the technical. That's more of like, do we have a firewall, do we have an intrusion detection system, do we have software that's monitoring things.
We have the operational side of this. This is the procedures that we're following: what kind of procedures do we follow to do our day-to-day functions throughout the company.
And then you have the managerial. It's kind of like the operational — in fact, there's a lot of confusion between the operational and managerial. The managerial is more of like, are we doing the risk assessments, are we managing the risk side of things. So it's more of the security program side of this, versus the operational, which would be the rest of the business. Now, I don't know that there's necessarily a really clear line dividing this managerial and operational, so really managerial is not being used as much anymore. In fact, NIST has taken it away as something that they define as being a type of control, although you still see it in the Security+.
We can also break down controls into different types, whether it's preventative, deterrent, detective, corrective, recovery, compensating or directive.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →