Common Controls
Common controls are security protections put in place once at an organizational or enterprise level and then reused, or 'inherited,' by multiple information systems instead of each system building its own version. This approach lets many systems rely on a shared safeguard rather than duplicating the same effort separately. Note that the vendor product usage of 'common control' in software development is unrelated to this cybersecurity meaning.
As defined by NIST, a common control is a security control that is inherited by one or more organizational information systems. Responsibility for a common control's development, implementation, assessment, and monitoring generally rests with a designated common control provider, an organizational official accountable for that control's lifecycle. Inheritance does not eliminate a system owner's responsibility to confirm that an inherited control adequately addresses the receiving system's specific requirements, and residual or system-specific portions of a partially inherited (hybrid) control typically remain the receiving system's responsibility. Practitioners should verify the current authoritative definitions and any applicable tailoring against the relevant NIST and CNSS publications, as terminology and control baselines evolve across revisions.
Why it matters
Common controls are a foundational efficiency mechanism in the Risk Management Framework (RMF) and similar authorization processes. Rather than requiring every information system to independently design, implement, assess, and monitor safeguards such as physical facility protections, personnel security screening, or enterprise-wide network defenses, an organization can establish these once and allow multiple systems to inherit them. This reduces duplicated effort, promotes consistency across an organization's security posture, and can streamline the assessment burden when a system pursues its authorization.
The concept also introduces accountability that practitioners must handle carefully. Because responsibility for a common control's development, implementation, assessment, and monitoring rests with a designated common control provider, a weakness in a widely inherited control can propagate risk across every system that relies on it. A single deficiency at the enterprise level can therefore affect many systems simultaneously, which makes clear ownership and ongoing monitoring essential.
A common expert-flagged mistake is treating inheritance as a way to offload responsibility entirely. Inheritance does not eliminate a system owner's obligation to confirm that an inherited control adequately addresses that system's specific requirements. Where a control is only partially inherited as a hybrid, the residual or system-specific portions typically remain the receiving system's responsibility. Assuming a control is fully covered simply because it appears on an inheritance list is a frequent source of gaps.
Who it's relevant to
Inside Common Controls
Common questions
Answers to the questions practitioners most commonly ask about Common Controls.