Controls Glossary

Browse 21 controls terms defined in plain English, from the cultural dictionary of computing.

21 Controls Terms

Account Lockout
A security control that temporarily or permanently blocks account access after too many failed authentication attempts. Lockout policies can slow brute-force...
Anti-Phishing
Focused on preventing, detecting, or reducing phishing attacks through technical controls, user training, or both. Anti-phishing measures span mail filtering,...
Baseline Security
The minimum acceptable set of security controls, settings, and practices required across systems or environments. Baseline security gives organizations a floor...
Bypass
A method of circumventing a security control, policy, or expected validation path without directly disabling it. Bypasses matter because a control can appear...
Data Protection
The combined technical, administrative, and legal measures used to keep sensitive data confidential, accurate, available, and appropriately handled. It spans...
Inspection
The examination of traffic, files, requests, or system behavior by a security control to decide whether activity is safe, suspicious, or disallowed. Inspection...
Internal Audit
An audit conducted by an organization's own internal audit function to evaluate whether controls, processes, and risk management practices are designed and...
IT Governance
The structures and decision processes used to ensure technology investments, risks, policies, and operations are aligned with organizational goals and...
Multi-Layered Defense
A security approach that uses several complementary controls at different layers so the failure of one does not immediately lead to full compromise....
Operational Risk
The risk of loss or harm caused by failed processes, human error, system breakdowns, poor governance, or external events affecting operations. In security...
Policy Enforcement
The technical and procedural actions used to ensure defined security policies are actually applied rather than merely documented. Policy enforcement can...
Preventative Control
A security control designed to stop an unwanted event, action, or compromise from occurring in the first place rather than merely detecting or documenting it...
Process Security
The protection built into business and technical processes so they cannot be abused, bypassed, or manipulated to create security failures. Process security...
Program Security
The overall security of a defined program, initiative, or managed set of activities, including its governance, staffing, controls, objectives, and measurement....
Protection Level
A defined tier or category describing how strongly something must be protected based on sensitivity, impact, or regulatory requirements. Protection levels are...
Protection Mechanism
A specific technical or procedural safeguard used to prevent, detect, or limit harm from threats or failures. Protection mechanisms range from memory...
Residual Risk
The risk that remains after security controls, mitigations, or remediation steps have been applied. Residual risk is what decision-makers must consciously...
Restriction
A limit or constraint placed on an action, permission, configuration, or data flow to reduce risk or enforce policy. In security, restrictions may apply to who...
Risk Control
A safeguard or process put in place to reduce the likelihood or impact of a particular risk. Risk controls may be preventative, detective, corrective, or...
Risk Mitigation
The reduction of risk through controls, process changes, redesign, monitoring, or other actions that lower likelihood or impact. Mitigation does not always...
Risk Reduction
The decrease in the likelihood or impact of a risk after controls, remediation, redesign, or operational changes are put in place. Risk reduction is the actual...

Related Topics