Skip to content

Glossary · Information security

Control

A measure that reduces risk, by modifying a threat, a vulnerability, or the impact of an incident.

A control is any safeguard or countermeasure that lowers risk. Controls can be technical, such as encryption, organizational, such as a policy, physical, such as a locked door, or people-related, such as training.

Controls are often described as preventive, detective, or corrective, depending on whether they stop an incident, spot it, or limit its damage. ISO/IEC 27001 Annex A is a widely used reference catalogue of controls.

Terms matter when they become defensible work.