Articles

Organisational, technical and physical controls: three families of control

How NIST sorts controls by who executes them, and where physical controls sit.

Reading: 5 minCybersecurity Governance

Article cover: Organisational, technical and physical controls: three families of control

A control’s class answers a question that “how important is this control” does not: who or what executes it. The NIST corpus behind this sheet sorts controls into three classes — management, operational and technical — and places physical and environmental protection in the operational class, as a family in its own right rather than a fourth kind of control. This sheet sets out that split, says where the physical controls sit, and shows why a gap in one class surfaces as a failure in another.

Three classes, and the wording that carries them

SP 800-12 Rev. 1 defines a security control as “the management, operational, and technical controls (i.e., safeguards or countermeasures) prescribed for a system to protect the confidentiality, availability, and integrity of the system and its information” (line 415; the glossary repeats the definition at line 4356, with the criteria ordered confidentiality, integrity and availability). SP 800-100 records that selected controls “are grouped into one of the three categories of management, operational, or technical controls, and are either preventive or detective in nature” (line 5205) — two classifications in one sentence. The preventive, detective and corrective grouping is the sibling sheet’s subject; the two are orthogonal, and a control has one of each.

The dividing test: what executes the control

SP 800-100 then defines the classes themselves (lines 6100–6117). Management controls “focus on the management of the information system and the management of risk for a system”. Operational controls address methods “focusing on mechanisms primarily implemented and executed by people (as opposed to systems)”. Technical controls “focus on security controls that the computer system executes”, protecting automatically against unauthorised access or misuse.

class        executed by           shape of the control
management   management decisions  policy, risk decision, authorisation
operational  people and process    a task a person performs, a procedure, a guard
technical    the system            an enforced setting the system applies itself

The class is assigned by dominant characteristic

The class is a label about the usual executor, not a claim about a control’s nature. SP 800-100’s footnote 75 is explicit: families “are assigned to their respective classes based on the dominant characteristics of the controls in that family”, and “many security controls, however, can be logically associated with more than one class” (lines 6107–6112). Its example is CP-1, the contingency-planning policy control, “listed as an operational control but also has characteristics that are consistent with security management”.

Physical and environmental protection is a family, not a class

The catalogue’s family table gives twenty families, PE among them (lines 1701–1710 of SP 800-53 Rev. 5), and PE, Physical and Environmental Protection, opens at §3.11 (line 12149). Its first three controls show how much of that family is people and procedure. PE-1 requires policy and procedures to be developed, documented and disseminated, and states that “Simply restating controls does not constitute an organizational policy or procedure” (PE-1, line 12153, quoted at line 12200). PE-2 requires a list of individuals authorised for the facility, credentials for them, review of the list, and removal when access is no longer required (line 12213). PE-3 requires enforcement at defined entry and exit points, access logs, escorting of visitors, and securing and changing keys and combinations (line 12273). SP 800-12 Rev. 1 says the family covers the physical facility, its geographic location and its supporting facilities (lines 3475–3498). SP 800-100’s class table (2006) settles the placement: PE sits in the operational class, beside personnel security, contingency planning and incident response (Table 11-1, lines 6081–6089).

A gap in one class shows up as a failure in another

The three classes are layers of one programme, not three drawers. Technical enforcement cannot force people to follow a procedure: “Management controls also play an important role in policy enforcement, so neglecting them would be detrimental to the organization”, SP 800-12 Rev. 1 adds, because deviations from policy “may be difficult to implement easily with some technical controls” (lines 1803–1806). The reverse dependency is just as direct — technical controls “are installed, maintained, and used by support and operations staff”, who create the user accounts (lines 2682–2688). Assurance obeys the same rule: “assurance is not only for technical controls, but for operational controls as well”, followed by the questions that test it — has the contingency plan been tested, are policies understood and followed (lines 2436–2441). Where they can live differs too: many controls in the physical and environmental protection family are inheritable and are “good candidates for common control status” (lines 1908–1914).

A policy nobody enforces is a technical failure waiting to be logged, and a door held open defeats the controls behind it. That reading is this sheet’s interpretation, not a quotation.

The vocabulary this sheet uses

The roadmap’s labels — organisational, technical and physical — match the Annex A structure of ISO/IEC 27001:2022 (organisational, people, physical and technological), which is not in this corpus; the corpus’s own vocabulary is different: the three-way split is a class, and family is a group such as PE (SP 800-100, lines 6068–6070). The sheet uses the NIST names: only those can be pointed at a line in a document that was read.

Level and prerequisites

L2 — operational: name a control’s class from what executes it, place a physical control in the catalogue’s own family, and read a gap in one class as a likely failure in another. Prerequisites are the L1 sheet on least privilege and defense in depth and the L1 sheets on ownership; the preventive, detective and corrective classification is the sibling sheet.

Where to go next

References

  • NIST — An Introduction to Information Security (SP 800-12 Rev. 1, 2017) — https://doi.org/10.6028/NIST.SP.800-12r1 — the definition of security controls and the glossary entry (lines 415, 4356–4359), management controls and policy enforcement (1803–1806), assurance for operational and management controls (2436–2441), support and operations staff running technical controls (2682–2688), and the physical and environmental protection family with its three areas (3475–3498).
  • NIST — Information Security Handbook: A Guide for Managers (SP 800-100, 2006) — https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-100.pdf — the three categories of selected controls (5204–5205), the classes-and-families introduction (6068–6073), Table 11-1 mapping each family to its class (6075–6095), the definitions of management, operational and technical controls (6097–6117), and footnote 75 on assignment by dominant characteristic, with the CP-1 example (6107–6112).
  • NIST — Security and Privacy Controls for Information Systems and Organizations (SP 800-53 Rev. 5, 2020) — https://doi.org/10.6028/NIST.SP.800-53r5 — the security and privacy control families table (1697–1710, with the count stated in footnote 25 at line 1720), common controls and inheritable families (1908–1914), the physical and environmental protection family heading (12149), PE-1 (12153, with the quoted discussion sentence at 12200), PE-2 (12213) and PE-3 (12273).