Critical control
A critical control is a control that is crucial to preventing a material unwanted event or mitigating its consequences — one whose absence or failure would significantly increase the risk despite other controls being in place.
Not all barriers are equal. On a well-built bowtie, a handful of controls carry most of the protection — and the ICMM's widely adopted definition captures the test: a control is critical if its absence or failure would significantly increase the risk despite the existence of the other controls.
That last clause does the work. It rules out controls that merely duplicate protection somebody else already provides, and it rules in the ones the whole system quietly leans on. A practical second test: if this control failed today, would you expect to stop the activity? If the honest answer is yes, it is critical; if the honest answer is "we'd carry on and note it", it probably is not.
Designating a control critical is a commitment, not a label. Critical controls are the ones that warrant a written performance standard, defined verification in the field and in the system, named ownership, and reporting when they degrade — the machinery of critical control management.
A bowtie makes the selection visible: controls that appear across multiple threat lines, or stand nearly alone between a threat and the top event, announce their own criticality. The product's control summary ranks controls by exactly that linked frequency — see it in any worked template.
Last reviewed 2026-08-09 · Back to the glossary
See the method in working software.
Six worked bowtie examples ship with the product — open one read-only, no sign-in, and read every control in full.