Security Controls
Security controls are the organisational, technical and physical safeguards an enterprise deploys to protect information systems and data against unauthorised access, modification, destruction or loss of availability. ISO/IEC 27001:2022 Annex A catalogues 93 controls across four themes (Organizational, People, Physical, Technological); NIST SP 800-53 Rev 5 catalogues roughly 1,006 controls across 20 families; CIS Critical Security Controls v8.1 condenses the same idea into 18 controls and 153 safeguards mapped to three implementation groups (IG1, IG2, IG3). In practice, every effective security programme layers preventive, detective, corrective and compensating controls into a defence-in-depth model under an ISMS or GRC framework.
Security Controls — Frameworks, Categories and How to Choose
TL;DR — What is a security control?
A security control is a discrete, testable safeguard that reduces a specific information security risk. The same concept is called a control in ISO/IEC 27001:2022 Annex A, a security and privacy control in NIST SP 800-53 Rev 5 and a safeguard in the CIS Critical Security Controls v8.1. Every mature security programme combines three implementation types — technical (firewall, EDR, MFA, AES-256), administrative (policy, procedure, training, vendor risk) and physical (access badges, CCTV, UPS, fire suppression) — across four functions: preventive, detective, corrective and compensating. The dominant frameworks in 2026 are ISO 27001:2022 (93 controls, four themes), NIST SP 800-53 Rev 5 (~1,006 controls, 20 families) and CIS Controls v8.1 (18 controls, 153 safeguards, three implementation groups). Effective programmes layer these controls into a defence-in-depth architecture governed by an ISMS aligned to ISO 27001 or the NIST Cybersecurity Framework 2.0.
ISO 27001 Annex A vs NIST SP 800-53 Rev 5 vs CIS Controls v8 — comparison
| Aspect | ISO/IEC 27001:2022 Annex A | NIST SP 800-53 Rev 5 | CIS Critical Security Controls v8.1 |
|---|---|---|---|
| Total controls | 93 controls | ~1,006 controls (incl. enhancements) | 18 controls, 153 safeguards |
| Structure | 4 themes: A.5 Organizational (37), A.6 People (8), A.7 Physical (14), A.8 Technological (34) | 20 families: AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR | 18 controls grouped by IG1 (basic), IG2 (foundational), IG3 (organisational) |
| Primary use case | ISMS certification, global B2B trust | US federal systems, FedRAMP, CMMC, defence supply chain | Pragmatic prioritised implementation for any size organisation |
| Maturity tiers / baselines | One baseline; tailoring via SoA and risk assessment | Three baselines (Low, Moderate, High) plus High-Value Asset overlay | Three Implementation Groups (IG1: 56, IG2: 130, IG3: 153 safeguards) |
| Certification | Accredited third-party certification by ISO 27001 auditors | No formal certification (used inside FedRAMP, CMMC, SOC 2 mappings) | No formal certification (used as implementation roadmap) |
| Best fit | Any enterprise selling B2B in EU / global markets | US government, defence contractors, high-assurance cloud | Mid-market firms, MSSPs, ICS/OT operators starting from zero |
| Mapping to NIST CSF 2.0 | Official Annex A ↔ CSF mapping published 2024 | Authoritative source for CSF Subcategories | CIS publishes CSF 2.0 mapping per safeguard |
What is a security control — formal definition
A security control is “a safeguard or countermeasure prescribed for an information system or organisation, designed to protect the confidentiality, integrity and availability of its information and to meet a set of defined security requirements” (NIST SP 800-53 Rev 5, definition aligned with FIPS 200). ISO/IEC 27000:2018 uses parallel language — “measure that maintains and/or modifies risk”. Both definitions emphasise three properties: a control must be deliberate (selected against a risk), testable (you can verify it works) and maintained (someone owns it).
Every control fits into two orthogonal taxonomies.
By implementation type:
- Technical (logical) controls — implemented in hardware, software or firmware. Examples: next-generation firewall, EDR/XDR (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne Singularity, Palo Alto Cortex XDR), multi-factor authentication, AES-256 encryption at rest, TLS 1.3 in transit, IAM with SSO via SAML 2.0 or OIDC, SIEM (Splunk, Microsoft Sentinel, Elastic Security, Wazuh), DLP, WAF, ZTNA.
- Administrative (organisational) controls — policies, procedures, training and processes implemented by people. Examples: information security policy approved by the board (ISO A.5.1), incident response runbook based on NIST SP 800-61 Rev 2, security awareness training (KnowBe4, Hoxhunt, SoSafe), vendor risk management (ISO A.5.19–A.5.23), background checks for privileged hires.
- Physical controls — protect facilities, equipment and media. Examples: badge readers, biometric locks, CCTV, mantrap entries, environmental controls (HVAC, UPS, generator), fire suppression (FM-200, NOVEC 1230), media sanitisation per NIST SP 800-88 Rev 1.
By function:
- Preventive — block an incident before it occurs (firewall rule denying inbound 3389, MFA, secure coding training, badged access).
- Detective — identify an incident in progress or after the fact (SIEM correlation rules, IDS/IPS like Suricata or Zeek, file integrity monitoring with Wazuh or Tripwire, CCTV review).
- Corrective — restore the system to a secure state after an incident (backup restore, patch deployment, account lockout reset, malware quarantine).
- Compensating — an alternative safeguard adopted when the primary control cannot be implemented, formally documented in the Statement of Applicability with the residual risk accepted by the risk owner.
Most real controls perform multiple functions. EDR is simultaneously a technical control, preventive (blocking known malware), detective (behavioural alerts to SOC) and corrective (automated rollback, isolation). ISO 27001 and NIST do not require single-classification — the taxonomy exists to make sure no function is left uncovered.
Major frameworks compared
ISO/IEC 27001:2022 and ISO/IEC 27002:2022
The global ISMS certification standard, published by the International Organization for Standardization. The 2022 revision consolidated the 114 controls of ISO 27001:2013 Annex A into 93 controls across four themes and introduced 11 new controls covering threat intelligence (A.5.7), cloud services (A.5.23), ICT readiness for business continuity (A.5.30), data leakage prevention (A.8.12), web filtering (A.8.23), secure coding (A.8.28) and others. ISO/IEC 27002:2022 is the accompanying implementation guidance — same controls, with detailed “what to do” descriptions for each. Transition deadline from ISO 27001:2013 to ISO 27001:2022 was 31 October 2025; from that date all new certificates use the 2022 revision. Certification is awarded by accredited bodies (BSI, DNV, TÜV, DEKRA, DQS, LRQA, Bureau Veritas) after a two-stage audit and renewed every three years with annual surveillance audits.
NIST SP 800-53 Rev 5
Published by the US National Institute of Standards and Technology in September 2020 with updates through 2023, NIST SP 800-53 Rev 5 catalogues approximately 1,006 controls and control enhancements across 20 families. It is mandatory for US federal information systems under FISMA and forms the technical backbone of FedRAMP (cloud authorisations), CMMC 2.0 (defence supply chain), the IRS Publication 1075, the CJIS Security Policy and many state-level frameworks. NIST SP 800-53B defines three baselines (Low, Moderate, High) plus a privacy baseline; NIST SP 800-53A provides the assessment procedures. Because NIST 800-53 is the most granular catalogue, it is widely used as the “source of truth” for control mappings — NIST CSF 2.0 Subcategories, SOC 2 Trust Services Criteria and the Secure Controls Framework all reference NIST 800-53 control IDs (AC-2, AU-12, SC-7 and so on).
CIS Critical Security Controls v8.1
The Center for Internet Security publishes the Critical Security Controls (formerly the SANS Top 20). Version 8.1 condenses cyber defence into 18 controls and 153 safeguards grouped into three Implementation Groups: IG1 (56 safeguards) for small enterprises with limited expertise, IG2 (130) for mid-sized enterprises with dedicated security staff, IG3 (153) for mature organisations facing targeted threats. CIS publishes mapping spreadsheets to NIST CSF 2.0, ISO 27001:2022, PCI DSS 4.0, HIPAA, FFIEC and the Cyber Insurance Coalition’s recommended baseline. The CIS Benchmarks (separate publication, 100+ system-specific hardening guides for Windows, Linux, macOS, AWS, Azure, GCP, Kubernetes, Docker, browsers and applications) operationalise CIS Control 4 (Secure Configuration of Enterprise Assets and Software).
COBIT 2019
ISACA’s COBIT 2019 is a governance and management framework for enterprise IT, not a pure security catalogue. It contains 40 governance and management objectives across five domains (EDM, APO, BAI, DSS, MEA). Security-relevant objectives include APO13 (Managed Security), DSS04 (Managed Continuity), DSS05 (Managed Security Services) and DSS06 (Managed Business Process Controls). COBIT is widely used by internal audit, IT audit and risk functions, and it explicitly maps to ISO 27001, NIST CSF and ITIL 4.
NIST Cybersecurity Framework 2.0
Released in February 2024, NIST CSF 2.0 is the successor to CSF 1.1. It organises cybersecurity outcomes into six functions — Govern (new), Identify, Protect, Detect, Respond, Recover — each broken into Categories and Subcategories. Govern is the headline change, elevating board-level risk oversight, supply chain risk management, roles and responsibilities, policy and oversight to a first-class function. CSF 2.0 is non-prescriptive; organisations select underlying controls from NIST SP 800-53, ISO 27001, CIS or any other catalogue. The CSF Implementation Examples (informative references published alongside the framework) translate each Subcategory into concrete safeguards drawn from NIST 800-53, SP 800-161 (supply chain) and SP 800-218 (Secure Software Development Framework).
ISO/IEC 27001:2022 Annex A walkthrough
The 93 controls of Annex A are organised into four themes. The numbers below are correct for the 2022 revision.
A.5 Organizational controls (37)
The governance and process backbone. Examples: A.5.1 Policies for information security (the master policy approved by top management), A.5.7 Threat intelligence (new in 2022 — formal threat intel programme feeding risk and detection), A.5.19 Information security in supplier relationships, A.5.23 Information security for use of cloud services (new in 2022 — explicit cloud due diligence and shared responsibility), A.5.24 Information security incident management planning and preparation, A.5.29 Information security during disruption (BCP), A.5.30 ICT readiness for business continuity (new in 2022 — bridges BCP into IT/DR). Auditors typically start the certification audit at A.5 because it sets the tone for everything else.
A.6 People controls (8)
Human-resources lifecycle. Examples: A.6.1 Screening (background checks during hiring), A.6.3 Information security awareness, education and training (annual mandatory training plus role-based for privileged users), A.6.7 Remote working (new in 2022 — explicit remote-work policy and controls), A.6.8 Information security event reporting (the “if you see something, say something” channel).
A.7 Physical controls (14)
Facility and environmental safeguards. Examples: A.7.1 Physical security perimeters, A.7.2 Physical entry controls (badges, mantrap, escort policies for visitors), A.7.4 Physical security monitoring (CCTV, intrusion detection), A.7.7 Clear desk and clear screen, A.7.11 Supporting utilities (UPS, generator, HVAC redundancy), A.7.14 Secure disposal or re-use of equipment (media sanitisation per NIST SP 800-88).
A.8 Technological controls (34)
The technical workhorses. Examples: A.8.2 Privileged access rights (PAM — CyberArk, BeyondTrust, Delinea), A.8.5 Secure authentication (MFA, preferably FIDO2/WebAuthn), A.8.8 Management of technical vulnerabilities (patch management, vulnerability scanning), A.8.9 Configuration management, A.8.12 Data leakage prevention (new in 2022 — Microsoft Purview, Symantec DLP, Forcepoint), A.8.16 Monitoring activities (SIEM, EDR, NDR), A.8.23 Web filtering (new in 2022 — DNS filtering with Cisco Umbrella, Cloudflare Gateway, Quad9, NextDNS), A.8.24 Use of cryptography, A.8.25 Secure development lifecycle, A.8.28 Secure coding (new in 2022 — OWASP ASVS, SAMM, SAST/DAST in CI/CD), A.8.29 Security testing in development and acceptance (penetration testing, dynamic and static analysis).
NIST SP 800-53 Rev 5 control families
Twenty families, each identified by a two-letter prefix. The most heavily used in commercial implementations:
- AC — Access Control (AC-2 Account Management, AC-3 Access Enforcement, AC-6 Least Privilege, AC-17 Remote Access). The largest family and the foundation of every Zero Trust architecture.
- AU — Audit and Accountability (AU-2 Event Logging, AU-12 Audit Record Generation, AU-6 Audit Record Review). Maps directly to SIEM scope.
- CM — Configuration Management (CM-2 Baseline Configuration, CM-6 Configuration Settings, CM-7 Least Functionality). Pairs naturally with the CIS Benchmarks.
- IR — Incident Response (IR-4 Incident Handling, IR-6 Incident Reporting, IR-8 Incident Response Plan). Aligned with NIST SP 800-61 Rev 2.
- SC — System and Communications Protection (SC-7 Boundary Protection, SC-8 Transmission Confidentiality and Integrity, SC-12 Cryptographic Key Establishment). The bulk of network and cryptography controls.
Other families: AT (Awareness and Training), CA (Assessment, Authorization and Monitoring), CP (Contingency Planning — BCP/DR), IA (Identification and Authentication), MA (Maintenance), MP (Media Protection), PE (Physical and Environmental Protection), PL (Planning), PM (Program Management), PS (Personnel Security), PT (PII Processing and Transparency), RA (Risk Assessment), SA (System and Services Acquisition), SI (System and Information Integrity), SR (Supply Chain Risk Management — heavily expanded in Rev 5 in response to SolarWinds).
CIS Critical Security Controls v8.1
Eighteen controls, ordered by impact. The first six are widely treated as the non-negotiable foundation.
- CIS 1 — Inventory and Control of Enterprise Assets. You cannot protect what you do not know exists. CIS 1.1 (Establish and Maintain Detailed Enterprise Asset Inventory) is the first safeguard everyone implements; tools include Lansweeper, Snipe-IT, ServiceNow CMDB, Microsoft Intune and Tanium.
- CIS 2 — Inventory and Control of Software Assets. Software Bill of Materials (SBOM), application allow-listing (Microsoft Defender Application Control, AppLocker), software composition analysis (Snyk, Sonatype Nexus IQ, GitHub Advanced Security).
- CIS 3 — Data Protection. Data classification, encryption at rest and in transit, retention policies, DLP.
- CIS 4 — Secure Configuration of Enterprise Assets and Software. Hardening per the CIS Benchmarks or DISA STIGs.
- CIS 5 — Account Management. Inventory of accounts, disable dormant accounts, separate admin accounts.
- CIS 6 — Access Control Management. MFA on all externally exposed services and all administrative accounts (CIS 6.3 and 6.5), role-based access, just-in-time elevation through PAM.
Controls 7-18 cover continuous vulnerability management, audit log management, email and web browser protections, malware defences, data recovery, network infrastructure management, network monitoring and defence, security awareness training, service provider management, application software security, incident response management and penetration testing.
Defence in depth — the layered control model
Defence in depth is the foundational design principle that no single control should be a single point of failure. An attacker must defeat several independent layers, and each layer simultaneously slows the attack and increases the probability of detection. A canonical five-layer model:
- User layer — security awareness training, phishing simulations (Cofense, Hoxhunt, KnowBe4), password managers (1Password, Bitwarden, Keeper), MFA with phishing-resistant factors (FIDO2/WebAuthn via YubiKey, Titan Security Key, Windows Hello for Business, passkeys).
- Endpoint layer — EDR/XDR, full-disk encryption (BitLocker, FileVault, LUKS), application allow-listing, patch management (Microsoft Intune, Tanium, Automox, Action1), hardening to CIS Benchmarks or DISA STIGs.
- Network layer — next-generation firewall, micro-segmentation, ZTNA (Cloudflare Access, Zscaler Private Access, Microsoft Entra Private Access), IDS/IPS (Suricata, Snort, Zeek), DNS filtering (Cisco Umbrella, Cloudflare Gateway, Quad9, NextDNS), egress filtering.
- Application layer — WAF (Cloudflare WAF, AWS WAF, F5 BIG-IP, Akamai App & API Protector, ModSecurity), secure SDLC under OWASP ASVS and OWASP SAMM, SAST/DAST/IAST in CI/CD (Snyk, Checkmarx, Veracode, Semgrep), dependency scanning, runtime application self-protection (RASP).
- Data layer — encryption at rest and in transit, DLP, data classification, tokenisation (PCI DSS 4.0 Req 3.5), IRM/DRM, immutable and air-gapped backup with 3-2-1-1-0 strategy.
Each layer should hold at least two or three independent controls, and detective controls (SIEM, EDR, NDR) should observe every layer. The defence-in-depth principle now sits alongside Zero Trust (NIST SP 800-207), which adds the rule that no layer implicitly trusts another — every request is authenticated and authorised on its own merits. The two concepts are complementary, not competing.
Selecting and implementing controls
Selecting controls is a risk-driven process, not a shopping exercise. The canonical five-step approach:
- Asset inventory. Catalogue every system, application, dataset, identity and device in scope. CIS Control 1 is the explicit starting point. Each asset gets a business owner and a classification (typically Public / Internal / Confidential / Restricted).
- Risk assessment. For each asset, identify threats (MITRE ATT&CK, STRIDE, PASTA), vulnerabilities (CVE, CWE) and existing controls. Estimate likelihood and impact using ISO 31000, NIST SP 800-30 Rev 1 or the quantitative FAIR (Factor Analysis of Information Risk) model. Output: a risk register with prioritised treatments.
- Framework selection and baseline. Choose a primary framework — ISO 27001:2022 for certification, NIST CSF 2.0 for governance maturity, NIST SP 800-53 for high-assurance and federal contexts, CIS Controls for pragmatic implementation — plus any mandatory sectoral overlay (PCI DSS 4.0, HIPAA, DORA, NIS2, FedRAMP). NIST 800-53 baselines (Low / Moderate / High) and CIS Implementation Groups (IG1 / IG2 / IG3) give a starting set of controls calibrated to risk appetite and capability.
- Control selection and tailoring. Map controls to risks. Document the result in the Statement of Applicability (SoA) under ISO 27001 — every Annex A control is listed as applicable or excluded with justification. Where a primary control cannot be implemented (legacy system without MFA, for example), document a compensating control and have the risk owner formally accept the residual risk.
- Implement, measure, iterate. Deploy controls in priority order. Measure with KPIs (percentage of endpoints covered by EDR, mean time to detect, percentage of patches applied within SLA) and KRIs (privileged accounts without MFA, days since last vulnerability scan, phishing click-rate). Audit at least annually — internal audits under ISO 27001 Clause 9.2, external certification audits and independent penetration tests. Improve through the Plan-Do-Check-Act cycle that sits at the heart of ISO 27001.
Most mid-market organisations achieve a 70-80% risk reduction with the same first ten quick wins: phishing-resistant MFA everywhere, EDR/XDR on every endpoint, immutable backups, fast patching, security awareness training with phishing simulations, network segmentation, centralised log management with a SIEM or MDR service, a password manager, privileged access management (PAM) for admin accounts and quarterly access reviews. Everything beyond that ten depends on the specific threat model and regulatory regime.
2026 control landscape
Several control areas have moved from “nice to have” to “expected” in 2026.
- AI and machine-learning controls. The NIST AI Risk Management Framework (AI RMF 1.0, January 2023) and ISO/IEC 42001:2023 (AI management systems) define controls for model risk, training data governance, prompt injection defence and adversarial testing. OWASP publishes the LLM Top 10 (Top 10 for Large Language Model Applications) and the ML Top 10 covering risks specific to AI workloads.
- Cloud shared responsibility. Every hyperscaler publishes a shared responsibility model — AWS, Microsoft Azure, Google Cloud and Oracle Cloud Infrastructure each split the security obligations differently between provider and customer. The Cloud Security Alliance Cloud Controls Matrix (CCM) v4 maps customer-side controls to ISO 27001, NIST 800-53, PCI DSS 4.0 and other frameworks. CSA STAR and FedRAMP attestations cover the provider side.
- Zero Trust architecture. NIST SP 800-207 (Zero Trust Architecture) and CISA’s Zero Trust Maturity Model 2.0 specify five pillars — Identity, Devices, Networks, Applications & Workloads, Data — with cross-cutting Visibility, Automation and Governance. Most large enterprises and US federal agencies (per Executive Order 14028) now operate to a published Zero Trust roadmap.
- Supply chain and software security. SBOM (Software Bill of Materials) in CycloneDX or SPDX format, code signing with Sigstore or vendor PKI, NIST SP 800-218 Secure Software Development Framework (SSDF), the EU Cyber Resilience Act (CRA, applicable from December 2027 with reporting obligations from September 2026) and the SLSA (Supply-chain Levels for Software Artifacts) framework collectively define the new supply chain baseline.
- Continuous compliance automation. Drata, Vanta, Secureframe, Hyperproof, Sprinto and AuditBoard automate evidence collection and continuous control monitoring against SOC 2, ISO 27001, HIPAA, PCI DSS and NIS2 — reducing audit fatigue and surfacing control failures in days instead of months.
- EU regulatory convergence. Three regulations dominate 2026 European compliance: NIS2 (Directive (EU) 2022/2555, in force since October 2024) with its 10 minimum cybersecurity risk management measures (Article 21), DORA (Regulation (EU) 2022/2554, applicable from 17 January 2025) for financial entities, and GDPR Article 32 (technical and organisational measures appropriate to the risk). ENISA publishes implementation guidance for NIS2 and DORA; national CSIRTs and the BSI in Germany, NCSC in the UK and ANSSI in France issue overlay requirements.
How nFlo helps
nFlo builds and operates end-to-end security control programmes for organisations preparing for or already certified against ISO 27001, NIS2, DORA and SOC 2. Typical engagements:
- SOC 24/7 — continuous monitoring and incident response operating the detective and corrective controls layer.
- IT security audit — gap assessment against ISO 27001, NIS2, DORA, NIST CSF 2.0 with a prioritised remediation roadmap.
- ISO 27001 implementation — full ISMS design and rollout, Statement of Applicability, internal audit programme and certification preparation.
- Penetration testing — independent verification that selected controls actually work.
- vCISO — fractional CISO building strategy, governance and the control selection roadmap.
FAQ
What is a security control in simple terms?
A security control is any safeguard or countermeasure that reduces a specific information security risk. ISO/IEC 27001 calls them controls, NIST SP 800-53 calls them security and privacy controls, CIS calls them safeguards — the same concept, three vocabularies. Examples include MFA (preventive, technical), SIEM alerting on failed logins (detective, technical), an incident response procedure (preventive, administrative) and a CCTV camera (detective, physical).
ISO 27001 vs NIST 800-53 vs CIS Controls — which one to pick?
For B2B certification and global trust signals, ISO/IEC 27001:2022 is the default. For US federal, defence supply chain and FedRAMP workloads, NIST SP 800-53 Rev 5 is mandatory. For mid-market organisations starting from limited maturity, CIS Critical Security Controls v8.1 (Implementation Group 1 first, IG2 next) is the most actionable. Most mature programmes use all three: ISO 27001 as the certification umbrella, NIST 800-53 / CSF 2.0 for technical depth, CIS Controls as the prioritised implementation backlog.
What goes into the Statement of Applicability?
The Statement of Applicability is the mandatory ISO/IEC 27001 document listing every Annex A control with applicability status (applicable or excluded), implementation status (implemented, partially implemented, planned) and justification linked to the risk assessment. Under the 2022 revision the SoA covers all 93 Annex A controls. Auditors use it as the spine of the certification audit and reuse it for SOC 2, NIS2 and DORA evidence packs.
What are preventive, detective, corrective and compensating controls?
Preventive controls stop incidents before they occur (firewall, MFA, training). Detective controls identify incidents in progress or after the fact (SIEM, IDS, audit logs, CCTV). Corrective controls restore systems after an incident (backup restore, patch deployment, malware quarantine). Compensating controls are alternative safeguards adopted when the primary control cannot be implemented, formally documented with risk acceptance by the risk owner. Most real controls perform two or three of these functions simultaneously.
How do you select security controls for an organisation?
Five steps: (1) asset inventory, (2) risk assessment using ISO 31000, NIST SP 800-30 or FAIR, (3) framework selection — ISO 27001 for certification, NIST 800-53 / CSF 2.0 for technical depth, CIS for prioritised implementation, plus sectoral overlays such as PCI DSS, HIPAA, DORA, NIS2, (4) control selection and tailoring documented in the Statement of Applicability, (5) implement, measure, iterate via the Plan-Do-Check-Act cycle. Most mid-market organisations cut risk by 70-80% with the same ten quick wins: MFA, EDR, immutable backup, patching, security awareness, segmentation, SIEM/MDR, password manager, PAM and quarterly access reviews.
Related terms
- ISO 27001 — ISMS certification standard
- NIST Cybersecurity Framework — six-function governance framework
- Access Control — the AC family in NIST 800-53
- Encryption — primary confidentiality control
- EDR — endpoint detection and response
- SIEM — security information and event management
- Zero Trust — never trust, always verify
- Compliance — regulatory and standards conformance
- DORA — EU Digital Operational Resilience Act
- Backup — corrective control against ransomware
Security controls are not a product you buy — they are a continuous programme of risk-informed safeguards. The frameworks differ in vocabulary and depth, but the underlying engineering is the same: identify what matters, layer preventive, detective, corrective and compensating measures across people, process and technology, and test them until the evidence proves they work.
Frequently asked questions
+ What is a security control in simple terms?
A security control is any safeguard or countermeasure that reduces the risk to an information asset. ISO/IEC 27001 calls them "controls" in Annex A; NIST SP 800-53 calls them "security and privacy controls"; CIS calls them "safeguards". All three terms describe the same thing — a discrete, testable measure that prevents, detects, corrects or compensates for a specific risk. Examples: multi-factor authentication (preventive technical control), SIEM alerting on failed logins (detective technical control), an incident response procedure (preventive administrative control), a CCTV camera at a server room (detective physical control). A mature security programme combines hundreds of these controls into a layered defence, governed by an ISMS aligned to ISO 27001 or the NIST Cybersecurity Framework 2.0.
+ What is the difference between ISO 27001, NIST 800-53 and CIS Controls?
Three frameworks, same underlying concept, different optimisation. **ISO/IEC 27001:2022** with Annex A is the global ISMS certification standard — 93 controls grouped into 4 themes, third-party audited, recognised in B2B contracts worldwide. **NIST SP 800-53 Rev 5** is the US federal baseline — roughly 1,006 controls across 20 families (AC, AU, CM, IR, SC, SI and so on), required by FedRAMP, CMMC and most US government contracts; it is the most granular catalogue and supports tailored baselines (Low, Moderate, High). **CIS Critical Security Controls v8.1** is the pragmatic implementation guide — 18 controls and 153 safeguards mapped to three implementation groups (IG1 for small enterprises, IG2 for mid-sized, IG3 for high-risk). Most organisations end up combining them: ISO 27001 for certification, NIST 800-53 / CSF 2.0 for technical depth and CIS for prioritised implementation.
+ What are the main categories of security controls?
Two orthogonal taxonomies. **By implementation type**: (1) **Technical controls** — implemented in hardware, software or firmware (firewall, EDR, MFA, AES-256 encryption, TLS 1.3, IAM, SIEM); (2) **Administrative controls** — policies, procedures, training and processes (information security policy, incident response runbook, security awareness training, vendor risk management); (3) **Physical controls** — protecting facilities, equipment and media (access badges, CCTV, biometric locks, UPS, fire suppression, secure disposal). **By function**: (1) **Preventive** — stop incidents before they happen (firewall, MFA, training); (2) **Detective** — identify incidents in progress (SIEM, IDS, audit logs, CCTV); (3) **Corrective** — restore systems after an incident (backup restore, patch deployment, incident response); (4) **Compensating** — alternative safeguard when the primary control cannot be implemented (extra monitoring instead of missing MFA, documented in the Statement of Applicability). ISO 27001:2022 Annex A and NIST SP 800-53 Rev 5 both expect controls to be classified along both axes during a risk assessment.
+ What is the Statement of Applicability (SoA) in ISO 27001?
The Statement of Applicability is the mandatory ISO/IEC 27001 document that lists every Annex A control and states (a) whether it is applicable to the organisation, (b) whether it is implemented and (c) the justification for inclusion or exclusion. Under the 2022 revision, the SoA must cover all 93 Annex A controls; exclusions must be justified against the risk assessment and the legal/regulatory context. Auditors use the SoA as the spine of the certification audit — they cross-check it against the risk treatment plan, control owners, evidence of implementation and the internal audit programme. A well-built SoA is also reused across SOC 2, NIS2 and DORA evidence packs, since most controls overlap; mapping tools such as the Cloud Security Alliance CCM and the Secure Controls Framework (SCF) accelerate this work.
+ How do you select the right security controls for an organisation in 2026?
Five-step risk-based process. (1) **Asset inventory** — identify systems, data, applications and people in scope; CIS Control 1 (Inventory of Enterprise Assets) is the foundation everything else builds on. (2) **Risk assessment** — use ISO 31000, NIST SP 800-30 Rev 1 or the FAIR quantitative model to estimate likelihood and impact for each threat-asset pair. (3) **Framework selection** — choose a primary catalogue (ISO 27001 for certification, NIST CSF 2.0 for governance maturity, CIS for pragmatic implementation, NIST SP 800-53 for federal / high-assurance contexts) plus any mandatory sector overlays (PCI DSS 4.0 for cards, HIPAA for US healthcare, DORA for EU finance, NIS2 for EU essential entities). (4) **Control selection and tailoring** — map controls to risks, apply a baseline (NIST 800-53 Low/Moderate/High or CIS IG1/IG2/IG3) and tailor with compensating controls where needed; document everything in the Statement of Applicability. (5) **Implement, measure, iterate** — deploy controls in priority order (typically MFA, EDR, immutable backup, patch management, security awareness first), measure KPIs and KRIs, audit at least annually and improve through the Plan-Do-Check-Act cycle. The 2026 reality is that supply chain controls (SBOM, code signing, third-party risk), AI/ML controls (NIST AI RMF, ISO/IEC 42001) and continuous compliance automation (Drata, Vanta, Secureframe, Hyperproof) have moved from optional to expected.