In terms of categories, controls can be:
Image
Administrative
Administrative are policy-driven controls, including employee training, incident response plans, and compliance frameworks. They shape human behavior to reduce risk.
Technical
Technical controls are implemented through technology, such as encryption, access control mechanisms, antivirus software, and authentication systems.
Physical
Physical controls involve the tangible protection of assets, including locked doors, biometric access, security cameras, and fire suppression systems.
Managerial
Some sources of information do not consider the managerial controls a category on its own, and instead they are simply spread into each of the other categories. However, in the Security+ exam content, it is given one of its own. Managerial controls are the overarching policies, procedures, and oversight mechanisms that guide an organization’s security practices and ensure the effective management of cybersecurity risks. They focus on the “who,” “what,” and “how” of cybersecurity, establishing the framework for the other categories.