Skip to content
atlas

People control

Also known as: human control, people measure

A safeguard aimed at staff themselves - screening, training, clear duties and what happens when someone joins or leaves.

Draft - this entry has not been reviewed yet.

Formal

A security control that works through the people in the organisation - background checks, terms of employment and confidentiality, awareness and training, reporting duties and the process when staff join, move or leave - one of the four control themes in ISO 27002.

In plain English

Like a kindergarten that checks a new helper's background, walks her through the daily routines on her first day and takes back her key when she leaves - the safety comes from who is let in and what they know.

In practice

At a pharmacy chain, new staff sign a confidentiality agreement and take a short course on handling customer data in their first week, and their access ends on their last day.

Why it matters

Many attacks and mistakes start with a person, so controls aimed only at machines leave the most common way in wide open.

Technical deep dive

ISO/IEC 27002:2022 clause 6 contains eight people controls that follow the employment lifecycle: 6.1 screening, 6.2 terms and conditions of employment, 6.3 information security awareness, education and training, 6.4 disciplinary process, 6.5 responsibilities after termination or change of employment, 6.6 confidentiality or non-disclosure agreements, 6.7 remote working and 6.8 information security event reporting. The theme is defined by the object of the control - the individual's behaviour, obligations and trustworthiness - rather than by who implements it; HR, line managers and the security function share ownership, which is a frequent source of gaps.

Screening must be proportionate to the role, the classification of the information accessed and the perceived risk, and constrained by law. In Denmark, requesting criminal-record extracts (straffeattest, or børneattest for work with children) is lawful only within specific rules, and processing of criminal-offence data is governed by GDPR Art. 10 together with section 8 of the Danish Data Protection Act (databeskyttelsesloven); blanket background checks for all staff are rarely justifiable. Terms of employment and NDAs create the legal basis for later sanctions and must explicitly survive termination, which is what 6.5 addresses.

Awareness is the most visible and most criticised people control. Annual click-through e-learning measures completion, not behaviour. Programmes that work tend to be role-specific (finance staff trained on payment-diversion fraud, administrators on privileged-credential hygiene), short and frequent, and measured by behavioural indicators such as the phishing report rate and time-to-report rather than click rate alone. Simulated phishing is contested: punitive or deceptive simulations can damage trust and reduce reporting, and the UK NCSC, among others, has warned against using click rates as a measure of success. The reporting duty in 6.8 only works if reporting is easy, fast and blame-free.

Regulation has extended people controls to leadership. NIS2 Art. 20(2) requires members of management bodies of essential and important entities to follow training, and Art. 21(2)(g) and (i) list cyber hygiene, training and human resources security among the mandatory measures. People controls mitigate insider threat and human error but cannot eliminate them; they are designed to work alongside technical controls such as least privilege, logging and data loss prevention, which limit what a single careless or malicious person can do. The standard contrast with technical controls is determinism: a configured block works identically every time, whereas a people control depends on judgement under pressure, fatigue and deception - the exact conditions social engineering exploits.

What to learn first

Everything this builds on, foundations first.

  1. Human factor
  2. →People control

Relationships

Requires
Human factor
Implemented by
Security awareness

Sources & further reading

Standards & official texts

  • ISO/IEC 27002:2022 (clause 6 - People controls)

Course material

  • Cyber Security Fast Track - Kursuskompendium, Ordliste (Kontrol - menneskelig foranstaltning)

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.