GRC › Module 6 › Lesson 1
Control Families
Control family literacy — access, audit, config, incident, physical — named family rows on YOUR `$GRC_LAB` fictional org control catalog only.
Visual · t37_control_families
Control families = named catalog rows. $GRC_LAB. Original Cyberlium.
Opening
Frameworks organize controls into families — name access, audit, and config family rows on YOUR lab catalog before claiming compliance on stranger org systems.
Control family literacy names: access control family category, audit and accountability family category, configuration management family category, incident response family category, and physical/environmental family category. Analyst documents control family card on `$GRC_LAB` fictional org template — five family rows with example control ID literacy stubs — without auditing stranger org systems without authorization, without copying live employer control matrices without scope, without fabricating control coverage for fraud. Cyberlium teaches GRC vocabulary on YOUR labeled notes under $HOME/cyberlium-lab/t37-grc/ — educational literacy only, not legal advice. Refused: stranger org audits, forged control catalogs, fake certification claims. Lab row: control family card (five families, example control ID stub, LAB label). chmod 600.
1. Named control family rows
Access, audit, config, incident, physical — five literacy anchors on YOUR lab catalog.
Each family cites `$GRC_LAB` template control ID — not copied stranger org matrices.
Command guide
Try these commands — Named control family rows
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
CIS Controls v8 — https://www.cisecurity.org/controls NIST CSF — https://www.nist.gov/cyberframework ISO 27002 — https://www.iso.org/standard/75652.html
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
export GRC_LAB=${GRC_LAB:-$HOME/cyberlium-lab/t37-grc}
curl -sS https://www.cisecurity.org/controls | head -10
cat > "$GRC_LAB/notes/control-families-named.txt" <<'EOF'
Control families — NAMED LITERACY:
CIS IG1: essential cyber hygiene (inventory, MFA, backups, patching)
ISO Annex A themes: organizational, people, physical, technological
NIST CSF functions: Govern/Identify/Protect/Detect/Respond/Recover
Mapping: one implemented control may satisfy multiple framework references
Ownership: each control needs owner + evidence type + test frequency
Lab: crosswalk table in controls/cis-nist-iso-crosswalk-stub.md
EOFCommand — copy this
grep -E 'CIS IG1|Annex A|Ownership|crosswalk' "$GRC_LAB/notes/control-families-named.txt"
Primary tools to practice this lesson: curl, grep. Reference sites: CIS Controls v8 (https://www.cisecurity.org/controls); NIST CSF (https://www.nist.gov/cyberframework); ISO 27002 (https://www.iso.org/standard/75652.html). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Framework link
Families appear in NIST 800-53 and ISO Annex A — link Module 4 framework literacy.
Family card feeds crosswalk work in Module 6-2 — same catalog thread.
3. $GRC_LAB boundary
Control notes from YOUR fictional org templates only — not live employer prod audits.
Refused: stranger org control theft, forged catalogs, fake certification artifacts.
4. What you ship: control family card
Five family rows + example control ID stub + LAB label + NEVER stranger org audit line.
5. What you record before the next lesson
Control family card path.
6. Wrong vs right: fraudulent certs vs YOUR lab templates
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Copy stranger org control matrix from public leak dump as 'control family research' without authorization.
Right
Control family card from `$GRC_LAB` fictional org template. Next: Crosswalks.
Mission: control family card
1) Name five control family literacy rows. 2) Map each to a lab catalog control ID stub. 3) LAB label on every sample row. 4) Write NEVER stranger org audit line.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “Access vs audit family — literacy split on lab catalog?”
Knowledge Check
APPLY: Control family literacy on Cyberlium uses:
Multiple choice
Knowledge Check
APPLY: True or False: Stranger org control audits belong in GRC lab.
True or False
Knowledge Check
APPLY: Control family card includes:
Multiple choice