Common Control Provider
A Common Control Provider is the organizational official responsible for managing security or privacy controls that multiple information systems share, or inherit, rather than each system implementing its own. By handling these shared controls centrally, the provider allows individual systems to rely on protections that are developed and maintained in one place. This role helps reduce duplicated effort across an organization's systems.
Per NIST terminology, a Common Control Provider is an organizational official responsible for the development, implementation, assessment, and monitoring of common controls, that is, security or privacy controls inherited by one or more organizational information systems. A common control is a control inherited by multiple systems, so the Common Control Provider is accountable for the lifecycle of those inheritable controls rather than for system-specific controls managed by individual system owners. The term Security Control Provider is used interchangeably in NIST glossary sources, though readers should verify the precise scope (security versus privacy controls) against the current authoritative NIST text, as this entry does not address specific implementation, assessment, or authorization procedures.
Why it matters
The Common Control Provider role exists because organizations rarely operate a single information system in isolation. Many protections, physical security of facilities, network boundary defenses, personnel security processes, or enterprise identity management, are logically implemented once and relied upon by numerous systems. Assigning a clear, accountable official for these shared controls lets individual system owners inherit those protections rather than reimplementing and separately assessing them, which generally reduces duplicated effort and helps promote consistency across an organization's security and privacy posture.
The role also introduces a critical accountability boundary that experts insist on preserving. When a system inherits a common control, the responsibility for developing, implementing, assessing, and monitoring that control rests with the Common Control Provider, not with the individual system owner. If that boundary is blurred, or if a common control is assumed to be adequately maintained when it is not, the weakness can propagate to every system that inherits it. Inheritance concentrates both benefit and risk, so the assurance any single system derives from a common control is only as strong as the provider's actual implementation and ongoing monitoring.
Because common controls are inherited, they must be continuously monitored rather than assessed once and treated as permanently satisfactory. A control that was effective at the time of an assessment may degrade, and any degradation affects all inheriting systems. Readers should treat this entry as a role definition only; it does not address the specific assessment, authorization, or continuous monitoring procedures that apply in a given environment, which must be confirmed against current authoritative NIST guidance and any applicable agency tailoring.
Who it's relevant to
Inside CCP
Common questions
Answers to the questions practitioners most commonly ask about CCP.