Study Hub

Domain 1.0: General Security Concepts

0/26
Objective 1.1Lesson 1 of 26

Control categories: who implements the control

Every safeguard in an organization can be sorted by the mechanism that delivers it. A firewall rule is enforced by hardware and software; a risk assessment policy is enforced by management decisions; a log-review checklist is enforced by people doing daily work; a locked server-room door is enforced by the physical world. These four delivery mechanisms are the four control categories: technical, managerial, operational, and physical.

CategoryImplemented byWorkplace examples
TechnicalSystems: hardware, software, firmwareFirewalls, disk encryption, antivirus, ACLs, IPS
ManagerialAdministrative decisions and oversightRisk assessments, security policies, vendor reviews
OperationalPeople performing day-to-day proceduresGuard patrols, awareness training, log reviews, media handling
PhysicalStructures and objects in the real worldFences, locks, bollards, badge readers, lighting

Technical controlA control enforced by technology rather than people — the system itself blocks, permits, encrypts, or logs. If it keeps working at 3 a.m. with nobody watching, it is probably technical.

Managerial controlA control that operates at the governance level: policies, standards, risk assessments, and planning activities that direct how security is managed. Older exams called these administrative controls.

Operational controlA control carried out by people as part of day-to-day work: guard patrols, awareness training, log reviews, backup rotation, media handling. If a human has to perform the task for the protection to exist, it is operational.

Physical controlA control that acts on the physical world to protect people, equipment, and facilities — fences, locks, bollards, lighting, vestibules. Physical controls matter because an attacker with hands on the hardware can eventually defeat most logical protections.

Don't confuse: Students constantly confuse managerial and operational controls. Ask who carries it out: a manager deciding and documenting (risk assessment, security policy) is managerial; a person doing a routine task (reviewing logs, changing backup tapes, running a training class) is operational. A written policy is managerial even though it is 'just paper.'

Exam tip: On the exam, a question may describe a badge reader on a door. The reader itself is a technical control, but the door and lock are physical — read carefully to see which element the question is really asking about.

Classifying controls by category is not academic busywork — it is how organizations find blind spots. A company whose entire budget went to firewalls and antivirus (technical) but that has no written policies (managerial), no training or log reviews (operational), and no door locks (physical) is deeply unbalanced, and an auditor will say so. Frameworks and audit checklists organize requirements by category precisely so that coverage gaps jump out. When you classify a control on the exam, you are practicing the same skill a security manager uses to balance a real program.

A company stations a guard at the lobby desk to check employee badges before allowing entry. Which control category best describes the guard?

A new policy requires every department to complete a formal risk assessment twice a year. Which control category is this?