Glossary · Term

Controls explained

Controls are the concrete security measures that reduce risk – MFA, backup tests, permission concepts, monitoring or approval processes.

At a glance
Meaning
Security measures that reduce risk
Examples
MFA, backups, permission concepts, monitoring
Standard
Annex A of ISO 27001 (93 controls)
Also known as
Technical and organisational measures (TOMs)
Updated
June 2026
Editorial team
Compliance Compass

What are controls?

Controls (measures) are the concrete levers with which risks are lowered – for example MFA, regular backups, clear access rights, encryption or monitoring. They are security put into practice: where Risk management describes what has to be protected, controls answer the question of how that happens. The term comes from the world of international standards; in data protection and in NIS2 the same thing is called Technical and organisational measures (TOMs).

Types of control

Controls, TOMs and standards

Annex A of ISO/IEC 27001 lists 93 recognised controls in four themes (organisational, people, physical, technological) – an internationally proven orientation that suits the implementation of NIS2 as well. In addition, the IT-Grundschutz compendium published by the BSI, a German standard, describes suitable measures according to the level of protection needed. In substance these controls largely coincide with the technical and organisational measures (TOMs) of Article 32 GDPR – only the terms differ.

Controls and risk management

Controls are not chosen at random but derived systematically from the risk analysis : for every relevant risk the fitting measure – no more, no less. Article 21 of NIS2 requires exactly this risk-based approach and calls for measures that are appropriate and proportionate to the risk. In practice: A mid-sized online retailer sees in its risk analysis that compromised administrator accounts are its biggest risk. As preventive controls it introduces MFA for all administrative accounts, restricts administrator rights to a few people on the principle of least privilege and encrypts the databases concerned. It adds detective controls by logging sign-ins and having unusual access reported automatically. For the emergency it keeps regularly tested backups and a clear contingency plan as responsive measures. Every single measure is documented, assigned to a responsible person and to a concrete risk, and given a review date. That makes it possible to show the supervisory authority that the protection is appropriate and that the requirements of the NIS2 Directive for risk-based security management are met.

Frequently asked questions

What are controls in IT security?

Controls are the concrete security measures that reduce risk – multi-factor authentication, regular backups, access controls, encryption or monitoring, for example. They are the practical implementation of the protection that risk management calls for, and they divide into preventive, detective and responsive controls. In law the same substance appears as technical and organisational measures, TOMs for short: Article 32 of the GDPR uses that wording, and Article 21 of NIS2 speaks of technical, operational and organisational measures.

Where are controls defined?

Recognised controls are found above all in Annex A of ISO/IEC 27001, which since the 2022 edition bundles exactly 93 measures into four themes: organisational, people, physical and technological. The IT-Grundschutz compendium published by the BSI, a German standard, also describes suitable controls for different levels of protection need, and other Member States publish comparable catalogues. Both sources offer proven orientation that works well for implementing the NIS2 requirements.

How do you choose the right controls?

The right controls are derived systematically from the risk analysis: for every relevant risk you choose an appropriate measure – no more and no less. That keeps effort and protective effect in proportion. Article 21 of NIS2 requires exactly this risk-based approach, calling for measures that are appropriate and proportionate to the risk. Every control should be documented, assigned to a responsible person and to a concrete risk, and be capable of being evidenced to the supervisory authority.

Further reading: ISO/IEC 27001 (information security management systems)

Measures

The right measures, evidenced

Compliance Compass derives controls from your risks and documents them in audit-proof form for NIS2.