The reference desk / In practice

Control

A process, configuration, or technology meant to reduce a named risk or detect a named failure.

What it means

A control is a safeguard with a specific job. It may prevent an unwanted action, detect a problem, or help restore service after a failure. Controls can be technical, physical, or procedural: a permission check, a locked equipment room, and an access review each address different conditions.

Describe the intended outcome before selecting a tool. Then identify who operates the control, where it applies, how it can fail, and what evidence shows it works. A policy document states an expectation; implementation and testing establish whether that expectation is met. Several controls may support one risk response, and one control may address several risks.

AN ILLUSTRATIVE SCENARIO

A finance payment change

A finance team wants to reduce the risk of fraudulent bank-detail changes. It requires an independent callback using a previously verified contact before changing a supplier's payment account. The control has an owner, a documented exception path, and a record of the verification. Buying an email filter alone would not establish this check. The team tests whether staff actually use the known contact details rather than the phone number supplied in the change request.

Put it to work

  1. Name the unwanted event and write the behavior the control must prevent, detect, or help recover from.
  2. Define its scope, operator, trigger, evidence, and exception process; include dependencies such as accurate contact records or working logs.
  3. Test the control with a representative safe case and review whether failures reach someone who can correct them.

How to check your work

Trace a recent transaction through the control. You should find the required check, its result, an accountable operator, and evidence that an intentionally invalid test would be caught.

Connect the ideas

  • Risk

    The potential for harm, assessed using what could happen, how likely it is, its impact, and what remains uncertain.

  • Residual risk

    The risk that remains after selected controls, including the uncertainty you still accept.

  • Defense in depth

    Layering independent controls so that one failure does not become a complete compromise.

  • Compensating control

    An alternative safeguard used in place of a specified control, with evidence that it provides comparable protection for the intended security objective.

Explore a field lesson

Find your next idea.

Tip: press / to open search. Escape closes this window.