# Security Control Overlay
**Entity class:** Security, Compliance, And Authorization Layer concept
**Security Control Overlay** is a governance and assurance mechanism that constrains who may use data, for what purpose, under what controls, and with what audit evidence. Security Control Overlay belongs in the ontology because AI can compute over this structure while analysts retain responsibility for interpretation and authorized action.
## Counterterrorism predictive-graph role
Its controls are part of the computational trust fabric, not peripheral paperwork: permissions, provenance, purpose, and auditability must remain machine-enforceable across systems. The analytic state should distinguish ground truth, observed evidence, inferred state, and predicted state.
## Relationships
- **domain router:** [[wiki/Assurance Infrastructure|Assurance Infrastructure]].
- **ontology neighbors:** [[wiki/Security Control|Security Control]] and [[wiki/Authorization to Operate|Authorization to Operate]].
- **synthesis:** [[wiki/Counterterrorism Predictive Graph|Counterterrorism Predictive Graph]] and [[wiki/Predictive Intelligence Loop|Predictive Intelligence Loop]].
## Sources
- [NIST SP 800-53 Rev. 5, Release 5.2.0, August 27, 2025](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)
- [ODNI — ICD 503, Intelligence Community Information Technology Systems Security Risk Management, September 15, 2008](https://www.dni.gov/files/documents/ICD/ICD_503.pdf)
**As of:** 2026-09-23