A security control acts as a tool to restrict a list of possible actions down to those that are allowed or permitted. An industry group, called the The Cloud Security Alliance, has documented a complete list of data security controls in a reference called the Cloud Control Matrix. This matrix is an important tool and is designed to help the security professional identify and selected data security controls, based on the applicable industry regulations or security governance environment.
Controls are generally described as being within one of three categories:
- Administrative: regulations, policies, laws, guidelines, and practices governing the overall information security requirements and controls
- Logical: Virtual technical and application controls such as firewalls, encryption, anti-virus software, and maker/checker routines
- Physical: used to manage physical...