Security controls are specific measures designed to reduce or manage identified information security risks to acceptable levels.
Security controls are specific measures, mechanisms, or activities that an organization designs and applies to address identified information security risks. In the context of ISO 27001 and an Information Security Management System (ISMS), security controls are selected and implemented based on a documented risk assessment and risk treatment plan.
Security controls can be:
Each control is defined so that it can be implemented, operated, monitored, and reviewed. ISO 27001 and its related guidance documents (such as ISO 27002) provide structured catalogues of control objectives and example controls that organizations can use when designing their ISMS.