controlsadministrative
Controlsadministrative, typically written as administrative controls, refers to non-technical measures designed to influence how people and processes behave to reduce risk. They are a foundational layer in risk management and security programs, complementing technical controls (such as access controls and encryption) and physical controls (such as badge access and locks). Administrative controls establish governance, policy, and procedures that guide daily operations.
Common examples include security policies, user access governance, role-based access controls, separation of duties, change and
Implementation typically begins with a risk assessment to identify gaps and requirements, followed by formal documentation
Limitations include reliance on human behavior and organizational culture; administrative controls can be bypassed or degraded