Control categories: who implements the control
Every safeguard in an organization can be sorted by the mechanism that delivers it. A firewall rule is enforced by hardware and software; a risk assessment policy is enforced by management decisions; a log-review checklist is enforced by people doing daily work; a locked server-room door is enforced by the physical world. These four delivery mechanisms are the four control categories: technical, managerial, operational, and physical.
| Category | Implemented by | Workplace examples |
|---|---|---|
| Technical | Systems: hardware, software, firmware | Firewalls, disk encryption, antivirus, ACLs, IPS |
| Managerial | Administrative decisions and oversight | Risk assessments, security policies, vendor reviews |
| Operational | People performing day-to-day procedures | Guard patrols, awareness training, log reviews, media handling |
| Physical | Structures and objects in the real world | Fences, locks, bollards, badge readers, lighting |
Technical control — A control enforced by technology rather than people — the system itself blocks, permits, encrypts, or logs. If it keeps working at 3 a.m. with nobody watching, it is probably technical.
Managerial control — A control that operates at the governance level: policies, standards, risk assessments, and planning activities that direct how security is managed. Older exams called these administrative controls.
Operational control — A control carried out by people as part of day-to-day work: guard patrols, awareness training, log reviews, backup rotation, media handling. If a human has to perform the task for the protection to exist, it is operational.
Physical control — A control that acts on the physical world to protect people, equipment, and facilities — fences, locks, bollards, lighting, vestibules. Physical controls matter because an attacker with hands on the hardware can eventually defeat most logical protections.
Don't confuse: Students constantly confuse managerial and operational controls. Ask who carries it out: a manager deciding and documenting (risk assessment, security policy) is managerial; a person doing a routine task (reviewing logs, changing backup tapes, running a training class) is operational. A written policy is managerial even though it is 'just paper.'
Exam tip: On the exam, a question may describe a badge reader on a door. The reader itself is a technical control, but the door and lock are physical — read carefully to see which element the question is really asking about.
Classifying controls by category is not academic busywork — it is how organizations find blind spots. A company whose entire budget went to firewalls and antivirus (technical) but that has no written policies (managerial), no training or log reviews (operational), and no door locks (physical) is deeply unbalanced, and an auditor will say so. Frameworks and audit checklists organize requirements by category precisely so that coverage gaps jump out. When you classify a control on the exam, you are practicing the same skill a security manager uses to balance a real program.
A company stations a guard at the lobby desk to check employee badges before allowing entry. Which control category best describes the guard?
A new policy requires every department to complete a formal risk assessment twice a year. Which control category is this?