StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 3: Information security program

Control design and selection: types, categories and control objectives

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

A control is any measure that modifies risk: a policy, process, device, practice or other action. A control objective is the statement of what the control must achieve, such as 'only authorized users can access payroll data'. Controls are selected to meet control objectives, which in turn come from the risk assessment and the organization's risk appetite. Starting with objectives keeps you from picking controls because they are familiar, fashionable or cheap, and it gives testers something clear to test against later.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan