physical action
163596·updated Sep 1, 2026A category of security control behavior in which compliance depends on deliberate, in-the-world conduct by a user — handling, carrying, locking away, or otherwise manipulating a tangible object or device — rather than on an automated or purely logical mechanism. NIST SP 800-171r3 uses the phrase in the context that "protection and control of mobile devices are behavior- or policy-based and require users to take physical action to protect and control such devices when outside of controlled areas." This distinguishes it from technical or administrative controls that operate without user involvement: the safeguard only fires if a person acts in the physical world (e.g., securing a device, locking a case, removing media). It is used in standards and compliance frameworks to flag control requirements that cannot be automated and therefore depend on training, policy, and human follow-through for their effectiveness.
Source
is behavior- or policy-based and requires users to take physical action tothe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
- NIST Special Publication 800 NIST SP 800-171r3
- Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A security control characteristic describing a deliberate, manual, in-the-world step that a user must personally perform — such as pressing a key to lock a screen, logging out, or physically securing a device — to satisfy a policy requirement. It distinguishes controls that depend on human bodily intervention from those that are automatically enforced by the system itself; a control classified this way cannot fire without the user consciously doing something in the physical world. In standards usage, the term signals an audit-relevant design choice: if the required step is not taken, the control fails because the system provides no automatic backstop, placing the compliance burden squarely on user behavior.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- physical actions
- possessive
- physical action's
- pluralpossessive
- physical actions'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 3 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A category of security control behavior in which compliance depends on deliberate, in-the-world conduct by a user — handling, carrying, locking away, or otherwise manipulating a tangible object or device — rather than on an automated or purely logical mechanism. NIST SP 800-171r3 uses the phrase in the context that "protection and control of mobile devices are behavior- or policy-based and require users to take physical action to protect and control such devices when outside of controlled areas." This distinguishes it from technical or administrative controls that operate without user involvement: the safeguard only fires if a person acts in the physical world (e.g., securing a device, locking a case, removing media). It is used in standards and compliance frameworks to flag control requirements that cannot be automated and therefore depend on training, policy, and human follow-through for their effectiveness.DR-088 backfill from the noun definition column