A security control is anything an organization puts in place to reduce risk: a firewall rule, a written policy, a guard at the door, a training session. Security+ asks you to sort controls in two independent ways. The first is the control category, which answers 'how is this control implemented, and who or what carries it out?' The SY0-701 objectives name four categories: technical, managerial, operational and physical. The second way, control type, answers 'what does it do?' (preventive, detective and so on) and is covered in the next lesson. Categories matter because a healthy security program uses all four. A company with excellent firewalls but no policies, no trained staff and an unlocked server room is still easy to breach, and auditors look for balance across categories.
Technical controls (sometimes called logical controls) are implemented by systems: hardware, software or firmware that enforces a rule automatically. Examples include firewalls, antivirus and endpoint detection and response (EDR) agents, encryption, multifactor authentication (MFA), operating system permissions, access control lists and intrusion prevention systems. Once configured, a technical control keeps working without a person deciding each time. That consistency is their strength; their weakness is that they only enforce what someone configured, so a wrong rule is enforced just as faithfully as a right one.
Managerial controls (also called administrative controls) are about direction and oversight. They are the decisions and documents that shape how security is run: security policies, risk assessments, the risk register, vendor risk assessments, the design of the awareness program, background check requirements and change management policy. If a control lives mainly on paper and describes what should happen or how risk is governed, it is probably managerial. Managerial controls rarely stop an attack directly; instead they decide which other controls exist and who is accountable for them.
Operational controls are carried out by people as part of day-to-day work. A guard checking badges, a help desk analyst following an identity verification procedure before resetting a password, staff running and testing backups, and employees attending awareness training are all operational. The line with managerial can feel subtle, so use this test: the policy that says 'all visitors must be escorted' is managerial, while the receptionist actually escorting visitors is operational. Managerial controls decide; operational controls do.
Physical controls protect the tangible environment: fences, bollards, locks, access control vestibules (mantraps), lighting, badge readers, cameras, fire suppression and locked server racks. They stop, slow or record people and vehicles moving through space. A badge reader is physical even though it contains electronics, because what it mainly protects is a doorway. Likewise a camera is a physical control. Do not let the presence of technology push you toward 'technical'; ask what the control guards. If it guards a space or an object you can touch, it is physical.
Here is a quick walk-through with one risk: laptops being stolen from an office. A policy requiring laptops to be locked away overnight is managerial. The cleaning crew supervisor checking desks each evening is operational. The cable locks and locked office doors are physical. Full disk encryption, which keeps the data unreadable if a laptop is taken anyway, is technical. Four categories, one risk, layered together. This is defense in depth expressed through categories, and it is exactly how you should think when a question asks which additional control would best close a gap.
Common mistakes: first, confusing category with type. 'Preventive' is never a category, and 'physical' is never a type. Every control has one of each, so a door lock is a physical, preventive control, and a camera is a physical, detective (and deterrent) control. Second, calling training managerial. Designing the program is managerial; delivering and attending training is operational. Third, labeling anything with a computer in it as technical. A badge reader or CCTV system is still physical. Fourth, assuming a control can only ever belong to one category. Some controls blend, and the exam usually asks for the best fit, so pick the category that matches the control's main purpose.
Exam questions usually describe a control and ask which category it belongs to, or give a scenario and ask which category of control is missing. Clue words help: 'configured', 'software', 'enforced by the system' point to technical; 'policy', 'assessment', 'governance', 'plan' point to managerial; 'performed by staff', 'procedure', 'guard', 'training session' point to operational; 'fence', 'lock', 'lighting', 'building' point to physical. When two answers look plausible, reread the question for the word 'implemented by' or 'carried out by', because that is what category measures.
Key terms
- Technical control
- A control enforced by hardware, software or firmware, such as a firewall, encryption or MFA.
- Managerial control
- A control that directs or governs security, such as a policy, risk assessment or vendor assessment; also called administrative.
- Operational control
- A control carried out by people in daily work, such as guards, backup procedures or delivering training.
- Physical control
- A control that protects tangible spaces and objects, such as fences, locks, bollards and cameras.
- Control category
- How a control is implemented and by whom; separate from control type, which describes what it does.
- Defense in depth
- Layering several different controls so that the failure of one does not expose the asset.
After a break-in at a branch office, a company reviews its controls. It finds it had strong technical controls (encrypted laptops and MFA) but no written physical security policy (managerial), no one checking that doors were locked at close (operational), and a rear door with a broken lock (physical). The remediation plan adds one fix in each category rather than buying another software tool, because the gap was never technical.
Check yourself
A company writes a rule that all servers must be patched within 14 days. An administrator then applies the patches each month. Which category is each?
The rule is managerial because it directs what should happen; the administrator applying patches is operational because a person performs the task.
Is a badge reader on a server room door a technical or physical control?
Physical, because its main purpose is to control entry to a physical space, even though it uses electronics.
An auditor finds firewalls, EDR and encryption but no risk assessment. Which category is weak?
Managerial, because nothing governs or justifies which controls are needed.
Why is 'detective' not a valid answer when asked for a control category?
Detective is a control type describing what a control does, not a category describing how it is implemented.