Controls
Policies, procedures, and technical measures designed to reduce risk and help ensure objectives are met.
Controls are the specific actions, processes, or technical safeguards an organization uses to reduce risk and achieve its objectives.
Examples include enforcing multi-factor authentication, requiring code review before deployment, or running regular access reviews. Controls can be preventive, detective, or corrective in nature.
In compliance frameworks, each requirement is typically mapped to one or more controls, and auditors look for evidence that those controls are designed appropriately and operating effectively.