Controls Glossary
Browse 21 controls terms defined in plain English, from the cultural dictionary of computing.
21 Controls Terms
- Account Lockout
- A security control that temporarily or permanently blocks account access after too many failed authentication attempts. Lockout policies can slow brute-force...
- Anti-Phishing
- Focused on preventing, detecting, or reducing phishing attacks through technical controls, user training, or both. Anti-phishing measures span mail filtering,...
- Baseline Security
- The minimum acceptable set of security controls, settings, and practices required across systems or environments. Baseline security gives organizations a floor...
- Bypass
- A method of circumventing a security control, policy, or expected validation path without directly disabling it. Bypasses matter because a control can appear...
- Data Protection
- The combined technical, administrative, and legal measures used to keep sensitive data confidential, accurate, available, and appropriately handled. It spans...
- Inspection
- The examination of traffic, files, requests, or system behavior by a security control to decide whether activity is safe, suspicious, or disallowed. Inspection...
- Internal Audit
- An audit conducted by an organization's own internal audit function to evaluate whether controls, processes, and risk management practices are designed and...
- IT Governance
- The structures and decision processes used to ensure technology investments, risks, policies, and operations are aligned with organizational goals and...
- Multi-Layered Defense
- A security approach that uses several complementary controls at different layers so the failure of one does not immediately lead to full compromise....
- Operational Risk
- The risk of loss or harm caused by failed processes, human error, system breakdowns, poor governance, or external events affecting operations. In security...
- Policy Enforcement
- The technical and procedural actions used to ensure defined security policies are actually applied rather than merely documented. Policy enforcement can...
- Preventative Control
- A security control designed to stop an unwanted event, action, or compromise from occurring in the first place rather than merely detecting or documenting it...
- Process Security
- The protection built into business and technical processes so they cannot be abused, bypassed, or manipulated to create security failures. Process security...
- Program Security
- The overall security of a defined program, initiative, or managed set of activities, including its governance, staffing, controls, objectives, and measurement....
- Protection Level
- A defined tier or category describing how strongly something must be protected based on sensitivity, impact, or regulatory requirements. Protection levels are...
- Protection Mechanism
- A specific technical or procedural safeguard used to prevent, detect, or limit harm from threats or failures. Protection mechanisms range from memory...
- Residual Risk
- The risk that remains after security controls, mitigations, or remediation steps have been applied. Residual risk is what decision-makers must consciously...
- Restriction
- A limit or constraint placed on an action, permission, configuration, or data flow to reduce risk or enforce policy. In security, restrictions may apply to who...
- Risk Control
- A safeguard or process put in place to reduce the likelihood or impact of a particular risk. Risk controls may be preventative, detective, corrective, or...
- Risk Mitigation
- The reduction of risk through controls, process changes, redesign, monitoring, or other actions that lower likelihood or impact. Mitigation does not always...
- Risk Reduction
- The decrease in the likelihood or impact of a risk after controls, remediation, redesign, or operational changes are put in place. Risk reduction is the actual...
Related Topics
- Risk Management (5 terms in common)
- Governance (4 terms in common)
- Mitigation (3 terms in common)
- Defense (2 terms in common)
- Content Inspection (1 terms in common)
- Policies (1 terms in common)
- Protection (1 terms in common)
- Prevention (1 terms in common)
- Security Programs (1 terms in common)
- Leadership (1 terms in common)
- Hardening (1 terms in common)
- Awareness (1 terms in common)
- Evasion (1 terms in common)
- Operational Security (1 terms in common)
- Standards (1 terms in common)
- Operations (1 terms in common)
- Compliance (1 terms in common)
- Enforcement (1 terms in common)
- Traffic Analysis (1 terms in common)
- Exceptions (1 terms in common)