Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient - No AI Slop!
Secure Controls Framework

Is a policy a control?

Direct Answer

Yes. A control is a “means of managing risk, including policies, procedures, guidelines, practices or organizational structures, which can be of an administrative, technical, management, or legal nature.”

Therefore, a policy is a control since a policy is merely an “administrative safeguard” and that meets the criteria of a control.