Security Controls Matrix

A practical control set for architecture reviews, requirements definition, control selection, and capability conversations.

Security Enterprise Architecture Controls Matrix

The matrix is intentionally visual: architects can scan the layers, control groups, and relationships before dropping into the detail.

Why It Exists

I started this Controls Matrix in about 2005 as a reference to add to design documents. It grew over time, found new uses, and remains a working tool for security architecture engagements.

It is not intended to be a compliance standard. It is a practical reference that helps people think through the control areas they need for a particular situation. Used well, it can support alignment with many standards without becoming another standard itself.

What It Is Useful For

  • Gap analysis: a broad reference for checking whether important control areas have been considered.
  • Requirements definition: a way to avoid missing key inputs when defining security requirements and selecting controls.
  • Capability reviews: a way to describe how people, processes, and controls work together to deliver a capability.
  • Architecture conversations: a shared map for discussing threats, operating constraints, and control choices.

Version 2.11

Version 2.11 introduces a re-engineered structure built around layers, making the document easier to maintain and expand. Several controls have also been reviewed and updated to better reflect current threats and operational realities.

The matrix is designed to evolve. The threat landscape changes, security controls change, and organisations need different things at different times.

Contribute

The framework is shared freely so others can benefit from it. If you use it, find it helpful, or have ideas for improvement, contact esa@assuredcontrol.com.

Downloads