Measure implemented to reduce risk—whether technical, administrative, or physical.
A control is any measure that modifies risk—reducing likelihood of threats, limiting impact if they occur, or enabling detection and response. Controls can be technical (firewalls, encryption), administrative (policies, procedures, training), or physical (locks, CCTV, access cards). Controls can be preventive (stop incidents), detective (identify incidents), or corrective (address incidents). Effective security requires layered controls addressing risks comprehensively.
Why It Matters
The DSC Perspective:
Controls are how you manage risk in practice. Understand what controls you have, what risks they address, and how effective they are. Defence in depth requires multiple, complementary controls.
