home/glossary/physical action

physical action

nounid 163596·updated Sep 1, 2026
verified

A category of security control behavior in which compliance depends on deliberate, in-the-world conduct by a user — handling, carrying, locking away, or otherwise manipulating a tangible object or device — rather than on an automated or purely logical mechanism. NIST SP 800-171r3 uses the phrase in the context that "protection and control of mobile devices are behavior- or policy-based and require users to take physical action to protect and control such devices when outside of controlled areas." This distinguishes it from technical or administrative controls that operate without user involvement: the safeguard only fires if a person acts in the physical world (e.g., securing a device, locking a case, removing media). It is used in standards and compliance frameworks to flag control requirements that cannot be automated and therefore depend on training, policy, and human follow-through for their effectiveness.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0165
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
is behavior- or policy-based and requires users to take physical action tothe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A security control characteristic describing a deliberate, manual, in-the-world step that a user must personally perform — such as pressing a key to lock a screen, logging out, or physically securing a device — to satisfy a policy requirement. It distinguishes controls that depend on human bodily intervention from those that are automatically enforced by the system itself; a control classified this way cannot fire without the user consciously doing something in the physical world. In standards usage, the term signals an audit-relevant design choice: if the required step is not taken, the control fails because the system provides no automatic backstop, placing the compliance burden squarely on user behavior.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems3 citations · 3 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.01.h ¶ 403.01.10.c ¶ 103.01.18.c

Classifications

Entity Type

Control92%llm-generatedllm:claude-haiku-4-5

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
physical actions
possessive
physical action's
pluralpossessive
physical actions'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 3 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A category of security control behavior in which compliance depends on deliberate, in-the-world conduct by a user — handling, carrying, locking away, or otherwise manipulating a tangible object or device — rather than on an automated or purely logical mechanism. NIST SP 800-171r3 uses the phrase in the context that "protection and control of mobile devices are behavior- or policy-based and require users to take physical action to protect and control such devices when outside of controlled areas." This distinguishes it from technical or administrative controls that operate without user involvement: the safeguard only fires if a person acts in the physical world (e.g., securing a device, locking a case, removing media). It is used in standards and compliance frameworks to flag control requirements that cannot be automated and therefore depend on training, policy, and human follow-through for their effectiveness.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.