4.3.2. Control Implementation and Integration
💡 First Principle: A control is only as effective as its integration into daily operations — deploying the technology is the easy part; getting staff trained on it and a clear owner assigned to it is what makes it actually function.
Deploying a new access control system is a technical milestone, not a completed implementation. The control isn't truly operating until it's integrated into existing processes (onboarding/offboarding workflows now route through it), staff are trained on how it changes their daily work, and clear operational ownership exists for maintaining it going forward. Skipping straight from "deployed" to "done" is one of the most common gaps between a program's documentation and its actual operating reality.
| Stage | "Deployed" Checklist | "Implemented" Checklist |
|---|---|---|
| Technology | Installed, configured | Integrated into existing workflows |
| People | N/A | Trained on new process |
| Ownership | N/A | Named operational owner assigned |
| Verification | N/A | First effectiveness check scheduled |
⚠️ Exam Trap: "Deployed" and "implemented" are often used interchangeably. The correct answer recognizes that process integration, staff training, and operational ownership are required before a control is truly effective — deployment alone does not equal implementation.
Reflection Question: A new data loss prevention tool was deployed six months ago, but no one owns tuning its alert rules, and staff were never trained on what to do when it flags something. Is this control implemented? What's missing?