Common Control
In a security and controls context, a common control is a safeguard that is put in place once but can be relied upon, or 'inherited,' by more than one system or program rather than being built separately for each. This approach lets multiple systems share the protection provided by a single control. Note that 'common control' also has an unrelated meaning in corporate accounting and regulatory law, where it refers to shared control over entities.
As defined in the NIST security controls context, a common control is a security control that is inherited by one or more organizational information systems or programs. Rather than being implemented and assessed independently within each system boundary, the control is provided at an organizational or shared level and its protection is inherited by the systems that rely on it. The term should be distinguished from system-specific controls, which apply to a single information system, and from hybrid controls, which combine common and system-specific elements. This entry addresses the security and controls usage; it does not cover the separate accounting and legal meaning of 'common control' (for example, common-control transactions under ASC 805 or 'common control' as defined for regulatory purposes under 29 CFR § 779.221), which concern shared or non-sole control over entities or net assets rather than inheritable safeguards.
Why it matters
In the NIST security controls context, common controls address a practical challenge: many safeguards, such as physical facility protections, personnel security processes, or shared network defenses, are not unique to any single information system but instead protect several systems at once. Defining these as common controls allows the protection to be implemented and assessed once at an organizational or shared level and then inherited by the systems that rely on it, rather than being duplicated, documented, and assessed independently within every system boundary. This can reduce redundant effort and promote consistency in how a given safeguard is applied across an organization.
The inheritance model also carries a concentration consideration. Because multiple systems depend on a single common control, a weakness or failure in that control may affect all of the inheriting systems simultaneously. Clear identification of which controls are common, and clear assignment of responsibility for their implementation and assessment, therefore matters for understanding where shared dependencies exist.
Finally, the term is a common source of confusion because 'common control' has an entirely separate meaning in corporate accounting and regulatory law, where it refers to shared control over entities or net assets. Under that usage, a common-control transaction does not meet the definition of a business combination because there is no change in control over the net assets, and 'common' control there is understood to include the sharing of control rather than sole or complete control by one party. Practitioners should be careful to establish which meaning is intended in a given document, as the two are unrelated.
Who it's relevant to
Inside Common Control
Common questions
Answers to the questions practitioners most commonly ask about Common Control.
