- Meaning
- Security measures that reduce risk
- Examples
- MFA, backups, permission concepts, monitoring
- Standard
- Annex A of ISO 27001 (93 controls)
- Also known as
- Technical and organisational measures (TOMs)
- Updated
- June 2026
- Editorial team
- Compliance Compass
What are controls?
Controls (measures) are the concrete levers with which risks are lowered – for example MFA, regular backups, clear access rights, encryption or monitoring. They are security put into practice: where Risk management describes what has to be protected, controls answer the question of how that happens. The term comes from the world of international standards; in data protection and in NIS2 the same thing is called Technical and organisational measures (TOMs).
Types of control
- Preventive: they stop incidents happening (access control, encryption, MFA, for example).
- Detective: they make incidents visible (monitoring, logging, alerting, for example).
- Responsive: they limit damage (backups, Incident response, contingency plans, for example).
Controls, TOMs and standards
Annex A of ISO/IEC 27001 lists 93 recognised controls in four themes (organisational, people, physical, technological) – an internationally proven orientation that suits the implementation of NIS2 as well. In addition, the IT-Grundschutz compendium published by the BSI, a German standard, describes suitable measures according to the level of protection needed. In substance these controls largely coincide with the technical and organisational measures (TOMs) of Article 32 GDPR – only the terms differ.
Controls and risk management
Controls are not chosen at random but derived systematically from the risk analysis : for every relevant risk the fitting measure – no more, no less. Article 21 of NIS2 requires exactly this risk-based approach and calls for measures that are appropriate and proportionate to the risk. In practice: A mid-sized online retailer sees in its risk analysis that compromised administrator accounts are its biggest risk. As preventive controls it introduces MFA for all administrative accounts, restricts administrator rights to a few people on the principle of least privilege and encrypts the databases concerned. It adds detective controls by logging sign-ins and having unusual access reported automatically. For the emergency it keeps regularly tested backups and a clear contingency plan as responsive measures. Every single measure is documented, assigned to a responsible person and to a concrete risk, and given a review date. That makes it possible to show the supervisory authority that the protection is appropriate and that the requirements of the NIS2 Directive for risk-based security management are met.
Frequently asked questions
What are controls in IT security?
Controls are the concrete security measures that reduce risk – multi-factor authentication, regular backups, access controls, encryption or monitoring, for example. They are the practical implementation of the protection that risk management calls for, and they divide into preventive, detective and responsive controls. In law the same substance appears as technical and organisational measures, TOMs for short: Article 32 of the GDPR uses that wording, and Article 21 of NIS2 speaks of technical, operational and organisational measures.
Where are controls defined?
Recognised controls are found above all in Annex A of ISO/IEC 27001, which since the 2022 edition bundles exactly 93 measures into four themes: organisational, people, physical and technological. The IT-Grundschutz compendium published by the BSI, a German standard, also describes suitable controls for different levels of protection need, and other Member States publish comparable catalogues. Both sources offer proven orientation that works well for implementing the NIS2 requirements.
How do you choose the right controls?
The right controls are derived systematically from the risk analysis: for every relevant risk you choose an appropriate measure – no more and no less. That keeps effort and protective effect in proportion. Article 21 of NIS2 requires exactly this risk-based approach, calling for measures that are appropriate and proportionate to the risk. Every control should be documented, assigned to a responsible person and to a concrete risk, and be capable of being evidenced to the supervisory authority.
Further reading: ISO/IEC 27001 (information security management systems)