What are administrative security controls?

According to their guide, “Administrative controls define the human factors of security. It involves all levels of personnel within an organization and determines which users have access to what resources and information.” Administrative security controls often include, but may not be limited to:

What are physical and technical security controls?

Meanwhile, physical and technical controls focus on creating barriers to illicit access—whether those are physical obstacles or technological solutions to block in-person or remote access. When selecting administrative security controls (or any other kind of security controls), it’s important to consider the following:

What is a security policy based on?

Tenable security policy must be based on the results of a risk assessment as described in Chapter 2. Findings from a risk assessment provide policy-makers with an accurate picture of the security needs specific to their organization. This information is imperative because proper policy development requires decision-makers to:

What is the security management process for administrative safeguards?

The first standard under Administrative Safeguards section is the Security Management Process. This standard requires covered entities to: “Implement policies and procedures to prevent, detect, contain and correct security violations.”

