openskills.info
Course Preview

Security Controls

Security controls are the safeguards an organization uses to protect its systems and data: technical measures such as access rules and firewalls, plus processes such as training, monitoring, and incident response. This course explains control types and families, how controls are selected, implemented, assessed, and monitored, and how security frameworks organize them.

itCybersecurity fundamentals and governance

Security Controls

A security control is a safeguard or countermeasure applied to protect an information system or an organization. It is the concrete step that turns a risk decision into something that operates: a firewall rule that rejects unwanted traffic, a policy that requires training before access, an audit log that records who changed what, a backup that restores data after an incident.

NIST defines a security control as the safeguards or countermeasures prescribed for an information system or an organization to protect the confidentiality, integrity, and availability of the system and its information. A control changes risk. It reduces the likelihood of an unwanted event, reduces its impact, or both. It does not remove uncertainty. After every control operates, some residual risk remains, and someone accountable must decide whether that remaining exposure is acceptable.

Why controls exist

Controls exist to make protection operational and testable. Risk analysis identifies what could go wrong and how bad it would be. Controls are the response: the specific safeguard assigned to a risk, with an owner, an implementation, and a way to check that it works.

That chain of reasoning gives controls their structure. An objective or obligation leads to a risk. The risk leads to a chosen response. The response leads to one or more controls. Each control has a statement of what it does, an owner accountable for it, and evidence that it operates. When that chain is visible, two different questions have answers. Coverage asks whether every important obligation and risk has a control. Effectiveness asks whether each control actually performs as intended. A large control catalog can provide broad coverage while its controls operate poorly. A smaller, well-run set can reduce more risk.

Control types

Controls are often described by what they do to an event. The common categories are preventive, detective, corrective, deterrent, and compensating.

Continue the course

This section is part of the paid course.

See pricing to subscribe, or log in if you already have access.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources