Cloud security controls are mechanisms that enforce security requirements in a running environment, distinct from the requirements themselves. Each control has four attributes: function (preventive, detective, corrective, deterrent, or compensating), class (administrative, technical, or physical), owner, and evidence source. The post maps key security domains — identity and access, data protection, network boundaries, workload and compute, and logging — and traces a single requirement (encrypting data at rest) through four major frameworks: CSA CCM, NIST SP 800-53, CIS Benchmarks, and FedRAMP. A practical checklist of verifiable statements per domain is provided, along with guidance on how controls shift across IaaS, PaaS, SaaS, and hybrid deployments. The post concludes with a section on how Orca Security's platform provides continuous evidence against 150+ frameworks using agentless scanning.