Skip to content
atlas

Don't confuse these

Organisational control vs People control

Organisational control

Controls & technical basics

A safeguard made of rules, roles and routines - who decides, who does what, and how work must be done.

Formal

A security control carried out through policies, processes, responsibilities and agreements - such as supplier management, access approval or an incident process - one of the four control themes in ISO 27002.

In plain English

Like the plan for a school trip - the teacher counts heads at every stop, children walk in pairs, and nobody leaves the group without telling an adult. No fence is needed.

In practice

A housing association writes down that a new user account needs the head of department's approval and that HR tells the IT department the same day someone leaves.

Why it matters

It is the largest group of controls in ISO 27002, and without clear rules and owners even good technology is set up and used at random.

People control

Controls & technical basics

A safeguard aimed at staff themselves - screening, training, clear duties and what happens when someone joins or leaves.

Formal

A security control that works through the people in the organisation - background checks, terms of employment and confidentiality, awareness and training, reporting duties and the process when staff join, move or leave - one of the four control themes in ISO 27002.

In plain English

Like a kindergarten that checks a new helper's background, walks her through the daily routines on her first day and takes back her key when she leaves - the safety comes from who is let in and what they know.

In practice

At a pharmacy chain, new staff sign a confidentiality agreement and take a short course on handling customer data in their first week, and their access ends on their last day.

Why it matters

Many attacks and mistakes start with a person, so controls aimed only at machines leave the most common way in wide open.

Shared connections

Atlas is in beta.