Control Family
Definition
A grouping of related controls within a catalogue. NIST SP 800-53 uses 20 families identified by two-letter codes: AC (Access Control), AU (Audit and Accountability), IA (Identification and Authentication), IR (Incident Response), and so on. ISO 27002 groups its 93 controls into four themes: Organisational, People, Physical, and Technological.
- Example catalogue
- NIST SP 800-53, 20 families
- Example codes
- AC, AU, IA, IR
- ISO 27002 grouping
- 4 themes: Organisational, People, Physical, Technological
Common questions
Why are controls grouped into families instead of listed individually?+
Grouping lets an assessor evaluate and report on a functional area, such as access control or audit logging, as a whole rather than reviewing every individual control item in isolation.
Do control families map one-to-one between different catalogues?+
No, groupings differ in granularity and theme between catalogues, which is precisely why a separate mapping exercise is needed to cross-reference individual controls rather than whole families.
Related terms
- Control Catalogue
- A structured list of security controls, each with an identifier, a statement of intent, and (in detailed catalogues) implementation guidance. Examples include...
- Crosswalk
- A published table that aligns controls from two frameworks side by side to show which controls address the same security objective. NIST,...
- Gap Analysis
- The process of comparing what a framework requires against what an organisation has actually implemented, to identify controls that are absent, partial,...
- Implementation Group (IG)
- A CIS Controls concept that divides the 153 safeguards across three tiers by organisational size and risk profile. IG1 (56 safeguards) covers...
- Unified Control Mapping
- An organisation-specific artefact that consolidates multiple crosswalks into a single table, adds columns for the organisation's own control implementations and evidence artefacts,...