Skip to content
atlas

Don't confuse these

Organisational control vs Physical security

Organisational control

Controls & technical basics

A safeguard made of rules, roles and routines - who decides, who does what, and how work must be done.

Formal

A security control carried out through policies, processes, responsibilities and agreements - such as supplier management, access approval or an incident process - one of the four control themes in ISO 27002.

In plain English

Like the plan for a school trip - the teacher counts heads at every stop, children walk in pairs, and nobody leaves the group without telling an adult. No fence is needed.

In practice

A housing association writes down that a new user account needs the head of department's approval and that HR tells the IT department the same day someone leaves.

Why it matters

It is the largest group of controls in ISO 27002, and without clear rules and owners even good technology is set up and used at random.

Physical security

Fundamentals

Protecting buildings, rooms and equipment so that nobody can simply walk in, take, break or plug into them.

Formal

The controls that protect the physical surroundings of information - sites, server rooms, devices and paper - against entry by outsiders, theft, damage and dangers such as fire, water and power loss. ISO 27002 groups them as its physical controls.

In plain English

The best lock on a diary is no help if someone can simply pick up the whole diary and walk off with it.

In practice

At a regional hospital, a visitor follows a porter through a card-locked door, finds an empty meeting room and plugs a small device into a free network socket; a no-following rule and switched-off sockets would have stopped it.

Why it matters

Anyone with hands on a machine can often get around its digital protection, and fire or flooding can end availability as surely as any attack.

Shared connections

Atlas is in beta.