CompTIA Security+ Course

Lesson 1.3: Security Control Categories

Introduction to Security Control Categories

When we defend an enterprise architecture, we implement safeguards called Controls. To systematically audit, deploy, and organize these safeguards, the cybersecurity industry classifies them. The four primary categories—Managerial, Operational, Technical, and Physical—represent implementation perspectives that classify who or what enforces a control.

The Medieval Castle Analogy

Imagine you are protecting a royal fortress. To achieve true defense-in-depth, you need different types of guards, barriers, and laws:

  • Managerial Control: The King's written royal charter specifying treaties, guard vetting policies, and emergency protocol procedures.
  • Operational Control: The shift rotations of the guards, the daily password challenges they verbalize, and the disaster response drills they run.
  • Technical Control: The hidden trapdoors, gears that lower the iron portcullis, and mechanical drawbridge release triggers.
  • Physical Control: The solid stone walls, deep defensive water moats, iron-bar structures, and high turrets.

The Four Implementation Perspectives

Managerial

Focus: Oversight & Strategy

Controls targeting administrative management, organizational policies, governance, assessments, and strategic risk postures. Executed by leadership and policy makers.

Key Examples:
  • Written Security Policies (e.g., AUP)
  • Regular Risk Assessments
  • Business Impact Analysis (BIA)
  • Compliance Auditing checks

Operational

Focus: People & Procedures

Controls executed primarily by people executing daily organizational processes rather than automated systems. Focused on physical-human interaction and workflow adherence.

Key Examples:
  • Security Awareness Training
  • Incident Response Procedures
  • Backup Configuration restores
  • User account onboarding workflows

Technical

Focus: Logical & Automated

Security safeguards executed and enforced by systems, software, hardware, or networks automatically without direct continuous human configuration.

Key Examples:
  • Firewall filtering policies
  • Data Encryption algorithms
  • Multi-Factor Authentication (MFA)
  • Intrusion Detection Systems (IDS)

Physical

Focus: Tangible Barriers

Controls designed to prevent real-world physical intrusion or damage to tangible hardware, facilities, structural rooms, and hardware infrastructure.

Key Examples:
  • Steel doors & deadbolts
  • Security perimeter fences
  • Motion sensors & CCTV cameras
  • HVAC units & Fire suppression

Test Your Knowledge

The Control Categorization Challenge

Read the security control card below, identify who or what enforces it, and select the correct Category!

Security Safeguard Card

Loading...