Security controls are technical and organizational measures and mechanisms that reduce risk, ensure confidentiality, integrity and availability, and support compliance requirements. They range from access controls and network segmentation to monitoring, logging and incident response processes. Clear classification and regular assessment improve effectiveness…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Security controls are organizational, technical, and physical measures used to address security risks.
The term grew from practice translating security requirements into verifiable protective measures. NIST SP 800-53 organizes such controls in a cataloged control framework.
A control addresses a risk or goal, assigns responsibility, and defines implementation and evidence. Controls can be preventive, detective, or corrective; a catalog does not replace risk-based selection and tailoring.
Abstract security goals become owned and testable measures.
Controls prevent, detect, or correct unwanted events.
Selection and tailoring depend on the system, risk, and control environment.
Security controls provide a shared language for protection measures, accountability, and evidence of effectiveness.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.