Terminology Index

Glossary

1801 terms

Open concept maps

Showing 1473-1504 of 1801 terms

S
32

Security Controls

Measures put in place to reduce security risks, technical, administrative, and physical, that together provide defense in depth. The fundamental building blocks of any security program.

Security controls are the specific measures, technical (firewalls, MFA, encryption), administrative (policies, training, processes), and physical (locks, badges), that mitigate risks. They come in preventive, detective, and corrective categories, layered to provide defense in depth. As a foundational security-foundations concept, controls are how policy and architecture become real protection. Frameworks like NIST 800-53, ISO 27001, and CIS Controls catalog them; programs select and implement those that fit their risks.

Introduced in: Security Foundations

Examples

  • Combining technical, administrative, and physical controls layered together.
  • Mapping selected controls to a framework catalog.
  • Choosing controls that mitigate identified risks.

No related terms linked yet.