5.1 Physical & Logical Access Control
5.1 Physical & Logical Access Control
Access control determines who or what may reach an organisational asset, what they are permitted to do with it and under which conditions that access should exist.
CISSP considers access broadly. Protection is required not only for applications and files, but also for systems, devices, facilities and services.
Physical
Control who can physically reach facilities, devices and infrastructure.
WHERE CAN YOU GO?Logical
Control which digital resources identities can use.
WHAT CAN YOU ACCESS?Least Privilege
Grant only the access required to perform the legitimate task.
ONLY WHAT IS NEEDEDThe Big Idea
Access control creates boundaries around organisational assets.
For every access path, ask:
Access Control Questions
Six Asset Types
CISSP explicitly expects access control to be considered across six categories of organisational assets.
Files, records, databases and other organisational data.
Servers, operating systems, platforms and computing environments.
Laptops, mobiles, network devices, removable media and specialised equipment.
Buildings, offices, data centres and restricted physical areas.
Business applications and their functions.
APIs, cloud services, infrastructure services and other capabilities.
5.1 Assets
Physical vs Logical Access
| Physical Access | Logical Access |
|---|---|
| Entering a building | Logging into a system |
| Entering a server room | Opening an administrative console |
| Opening a locked cabinet | Reading a protected file |
| Connecting to a physical network port | Being authorised onto the network |
| Accessing a laptop physically | Unlocking its operating system |
| Entering an evidence store | Opening the digital evidence repository |
Strong logical controls do not eliminate the need to protect the physical systems enforcing them.
Likewise, placing a server behind a locked door does not remove the need for logical authentication and authorisation.
Physical vs Logical
Secure both.
๐ค Subject & Object Who requests access and what are they trying to access?
An active entity requesting or performing access.
A resource that a subject attempts to access.
A payroll application reads salary information from a database.
Subject: payroll application/service identity.
Object: salary database records.
Applications, workloads, services and devices also access resources and therefore require controlled identities and permissions.
The Access Decision
Successfully proving identity does not mean the identity should be allowed to access every resource.
Access Flow
๐ฏ Least Privilege Grant only the permissions required for the task
Least privilege reduces the access available to users, processes, applications and services.
An application only needs to:
read customer product information.
Giving its service account full database administrator permissions creates unnecessary privilege.
A customer-service employee needs to:
They do not automatically require permission to:
Least Privilege
If an account is misused or compromised, the attacker's capabilities are constrained by the permissions available to that account.
๐ง Need-to-Know Access to information should be justified by the business requirement
Need-to-know focuses particularly on whether a person requires access to specific information in order to perform their duties.
Two employees have the same organisational seniority.
One works on a confidential acquisition.
The other does not.
Seniority alone does not create a need-to-know for the acquisition information.
Least Privilege vs Need-to-Know
Access should still correspond to an appropriate business or operational requirement.
โ Default Deny Permit required access rather than trying to predict every unwanted path
Everything is permitted unless a rule explicitly blocks it.
Access is denied unless an authorised rule explicitly permits it.
Start from no access, then add the access justified by legitimate requirements.
Default Deny
Access to Information
Information access should reflect its sensitivity, ownership, business purpose and applicable policy.
Restrict who may read, modify or delete files.
Limit access to appropriate databases, tables, records or operations.
Present information only to users whose role and business purpose justify it.
Separate information according to sensitivity or business need.
Protect information where confidentiality requires cryptographic protection.
Sensitive information access may require stronger logging and review.
A healthcare employee is authorised to use the patient-management system.
That does not necessarily mean they should be able to view:
every patient's complete medical record.
Application-level controls can further limit the information presented.
Encryption can protect information against unauthorised reading under certain conditions, but authorised systems still need to decide who may use the decrypted information.
Access to Systems
Systems provide multiple access paths, not just an ordinary user login.
Securing the normal login screen is insufficient if a forgotten management interface provides a second, poorly protected route into the same system.
System Access Controls
Provide only the functionality users require.
Restrict privileged interfaces more strongly than ordinary use.
Apply appropriate authentication, endpoint and network controls.
Non-human identities should receive only permissions needed by their function.
Exceptional access should be controlled, accountable and reviewed.
Physical or out-of-band administration should not bypass normal security governance.
๐ Privileged Access Administrative capability deserves stronger protection
Privileged access can modify systems, security configuration, identities, permissions and sometimes audit information.
Stronger Controls May Include
An administrator uses the same privileged account for:
Everyday activity uses a normal account.
Privileged activity requires a separate, strongly controlled administrative identity.
Privileged Access
Access to Devices
Devices may themselves contain information, credentials and connectivity into organisational environments.
Prevent unauthorised people from taking or physically manipulating devices.
Establish whether a device is recognised and permitted to interact with organisational resources.
Prevent unattended authenticated sessions from remaining openly accessible.
Use appropriate NAC or similar mechanisms to control device connectivity.
Restrict removable media and interfaces where they create unacceptable risk.
Device security policy should remain enforceable throughout its lifecycle.
An authorised employee plugs an unmanaged personal laptop into a corporate network.
The employee's identity may be legitimate.
The device itself may still fail the organisation's access requirements.
An authorised person does not automatically make every device they own suitable for accessing sensitive resources.
Access to Facilities
Physical access controls restrict movement from public areas toward increasingly sensitive organisational assets.
Physical Access Controls
An employee who needs access to an office floor does not automatically require access to the data centre, evidence room or network infrastructure areas.
๐ถ Tailgating & Piggybacking Authorised people can accidentally become an access path
Physical access controls can be bypassed when an unauthorised person enters behind someone who has legitimate access.
An employee authenticates with a badge.
A second person walks through the door before it closes without authenticating independently.
Possible Controls
Access systems should be designed so each individual is appropriately authorised for the protected area.
๐ชช Visitor & Contractor Access Legitimate presence does not require unrestricted movement
Visitor Access
Access to Applications
Application access should distinguish between being allowed to open an application and being authorised to perform particular functions inside it.
Several employees can log into the same banking application.
Their permitted activities may differ:
Application access should reflect the legitimate duties of each identity.
Application Access Can Operate at Different Levels
"Has access to the application" can still represent dozens of different permission levels.
Access to Services
Modern environments increasingly consist of services communicating with other services.
A mobile application uses a payment API.
The API should determine:
- which client is calling;
- which user or workload it represents;
- which functions it may invoke;
- which data it may access;
- how frequently it may perform sensitive operations.
A service should not receive unlimited access simply because no human user is directly involved.
๐ค Non-Human Access Applications and services can hold powerful privileges
Access-control design must account for identities used by software and infrastructure.
Common Risks
Service accounts are sometimes granted broad access for convenience.
Credentials may remain unchanged for years.
Nobody knows which team is responsible for an old account.
Multiple systems may use one identity, reducing accountability.
The application is retired while its account remains active.
Credentials may be stored insecurely in scripts or configuration files.
Protect Every Access Path
The strongest control on the main access path does not help if another weaker path reaches the same asset.
Security architects should understand all physical and logical routes to sensitive assets rather than evaluating the primary user interface only.
๐ฐ Access Control Defence in Depth One successful access decision should not unlock everything
Access Defence in Depth
๐ Context-Aware Access The same identity does not always need the same access under every condition
Access decisions can consider more than a username and static permission.
An administrator normally manages production from:
a managed privileged workstation on an approved network.
The same administrator attempts the action from:
an unmanaged device on an unknown network.
The identity is the same, but the security context is different.
โฐ Time-Limited & Just-in-Time Access Privilege does not always need to exist permanently
Permission exists continuously whether or not it is currently required.
Permission exists only for an authorised period.
A database administrator needs elevated production access for a 30-minute maintenance activity.
Permanent elevated access may be unnecessary if the organisation can provide controlled temporary privilege.
Access Duration
๐ฅ Separation of Duties A sensitive process may require more than one person
Separation of duties divides sensitive responsibilities so one person cannot independently complete an entire high-risk process.
Separation of duties can additionally ensure that one identity cannot complete every sensitive stage of a transaction.
Separation of Duties
2๏ธโฃ Dual Control Two authorised parties may be required together
Dual control requires two authorised entities to participate before a sensitive action can be completed.
Two authorised custodians may be required to access particularly sensitive cryptographic material.
SoD vs Dual Control
๐งพ Access Logging & Accountability Important access should be attributable
Logging provides evidence about how protected assets are accessed.
Useful Questions
If twenty administrators use one shared identity, determining who performed a particular action becomes more difficult.
๐ Access Reviews Access that was correct last year may no longer be correct today
Access should be reviewed because users, roles, systems and business requirements change over time.
An employee moves through four jobs over eight years.
Each new role adds permissions, but old access is never removed.
The user eventually holds much more access than their current job requires.
Access Has a Lifecycle
Accessing a Critical Database
A database administrator needs to perform planned maintenance.
A Payment System
A payment application has three users:
Creates payment requests.
Approves payment requests.
Manages the technical platform but does not automatically approve business transactions.
The ability to administer infrastructure should not automatically grant permission to perform sensitive business transactions.
One Account Is Compromised
Compromised account can:
Large blast radius.
Compromised account can:
Smaller blast radius.
Least Privilege
๐ CISSP Scenarios Identify the access-control principle
An employee's badge allows access to the office but not the data centre.
Which principle?
Physical least privilege.
A user successfully authenticates to an application but cannot open payroll records.
What does this demonstrate?
Authentication and authorisation are separate decisions.
A service account only needs to read one database table but has full database administrator privileges.
Which principle is violated?
Least privilege.
A senior executive requests access to highly sensitive project data unrelated to their responsibilities.
Which principle should be considered?
Need-to-know.
A firewall policy blocks all traffic except explicitly authorised communication.
Which principle?
Default deny.
A payroll application is permitted to read salary records.
The application is acting as which access-control entity?
Subject.
The payroll database record being read is which access-control entity?
Object.
An employee can log into a financial application but cannot approve payments.
What does this demonstrate?
Application access can be controlled at the function/action level.
One employee initiates a payment while another employee must approve it.
Which principle?
Separation of duties.
Two custodians must both participate before sensitive key material can be accessed.
Which concept?
Dual control.
A contractor repairing cooling equipment is given unrestricted physical access to the entire data centre.
What is wrong?
Physical access exceeds the legitimate business requirement.
An authorised employee opens a secured door and an unknown person follows directly behind without authenticating.
Which attack?
Tailgating.
A visitor can enter only reception and a meeting room for the duration of their appointment.
Which principle?
Physical least privilege and time-limited access.
An administrator uses a standard user account for email and a separate privileged account for server administration.
Which principle?
Separation of privileged and normal access.
Twenty administrators share one root account.
Which security property is weakened?
Accountability.
A user's privileges from four previous jobs were never removed.
Which problem?
Privilege accumulation / access creep.
A privileged permission automatically expires after a two-hour maintenance window.
Which principle?
Time-limited / just-in-time access.
A user's identity is valid but access is denied because the request originates from an unmanaged device.
Which idea?
Context-aware access control.
A legitimate employee connects an unapproved personal laptop to the corporate network.
What should be distinguished?
User trust from device trust.
Sensitive files are encrypted, so management decides that file permissions are unnecessary.
What is wrong?
Encryption does not replace logical access control.
A production server requires MFA through its normal interface, but an old management interface still accepts a shared password.
Primary lesson?
Every access path to the asset must be protected.
An employee can access an application but can view customer records only for their assigned region.
What does this demonstrate?
Access can be constrained at the data level, not only the application level.
An API is authenticated but its identity can invoke every administrative function even though it needs only one read operation.
Which principle is violated?
Least privilege for non-human identities.
An application has been retired but its privileged service account remains active.
What failed?
Access lifecycle management / deprovisioning.
A visitor's temporary badge continues working several months after the visit.
Primary issue?
Failure to revoke temporary physical access.
A database administrator can technically change records but policy does not permit the administrator to approve business transactions.
What important distinction?
Technical capability does not automatically equal business authorisation.
A security review confirms that users still require all permissions assigned to them.
Which activity?
Access review / recertification.
An employee changes department but retains permissions from their old department.
What should occur?
Access should be modified to reflect the employee's current responsibilities.
A user authenticates successfully but attempts an operation outside their permitted scope.
Which security decision should stop the action?
Authorisation.
A sensitive administrator session is recorded and attributable to one named administrator.
Which objective does this particularly support?
Accountability.
Recognise the Clue Words
Can Enter Building?
Physical boundary.
Physical AccessCan Open File?
Digital resource.
Logical AccessOnly Required Permission
Reduce privilege.
Least PrivilegeRequires This Information?
Business requirement for data.
Need-to-KnowDeny Unless Explicitly Allowed
Secure starting position.
Default DenyRequests Access
Active entity.
SubjectResource Being Accessed
Passive resource.
ObjectProve Identity
Is the claim genuine?
AuthenticationWhat Can You Do?
Permission decision.
AuthorisationWho Did It?
Trace action.
AccountabilityCreate + Approve Split
Divide responsibility.
Separation of DutiesTwo People Required Together
Joint participation.
Dual ControlFollow Through Door
Bypass individual admission.
TailgatingTemporary Admin Access
Remove standing privilege.
Just-in-Time AccessOld Permissions Accumulate
Access no longer matches role.
Privilege CreepPeriodic Permission Check
Still needed?
Access ReviewApplication Retired, Account Remains
Orphaned access.
Deprovisioning FailureUser Trusted, Device Not Trusted
Separate decisions.
Device Access ControlAdmin vs Everyday Account
Separate privileged use.
Privileged Access ControlAccess Depends on Device / Location
More than identity.
Context-Aware Accessโ ๏ธ Common CISSP Mistakes Access questions often test the distinction between identity and permission
Proving identity does not grant unlimited permission.
Both physical and logical access should follow legitimate business requirements.
Access to sensitive information should correspond to business need, not prestige.
Technical administration does not automatically justify performing business transactions.
Data can be strongly encrypted while excessive authorised access remains.
A locked server room does not replace operating-system and application permissions.
Strong system authentication does not remove the need to protect physical consoles and devices.
Services, applications, devices and workloads also need controlled access.
Application permissions can restrict individual functions, actions and records.
Roles and business needs change, so access requires review and eventual revocation.
Time-limited access can reduce unnecessary standing privilege.
Alternative management, service and physical paths must also be protected.
Shared identities make it more difficult to attribute activity to a specific person.
A legitimate user can still connect from an unsuitable or compromised endpoint.
Reviews should determine whether access remains appropriate rather than simply preserve historical permissions.
Quick Reference
| If you see... | Think... |
|---|---|
| Enter room / building | Physical Access |
| Open system / file / application | Logical Access |
| Minimum permissions | Least Privilege |
| Requires specific information | Need-to-Know |
| No access unless explicitly permitted | Default Deny |
| Entity requesting access | Subject |
| Resource being accessed | Object |
| Prove identity | Authentication |
| Determine permitted action | Authorisation |
| Trace actions to identity | Accountability |
| Divide sensitive tasks | Separation of Duties |
| Two people required together | Dual Control |
| Follow authorised person through door | Tailgating |
| Privilege only for maintenance window | Time-Limited / JIT Access |
| Old permissions remain after role changes | Privilege Creep |
| Periodic check of permissions | Access Review |
| Remove access when no longer required | Deprovisioning |
| Admin identity separate from normal identity | Privileged Access Separation |
| Access depends on device / location / risk | Context-Aware Access |
| Application or service accessing data | Non-Human Identity |
Physical & Logical Memory Aid
Access becomes more granular as you move closer to the asset.
Least Privilege Memory Aid
Right person ยท Right asset ยท Right action ยท Right time ยท Right context
5.1 Master Memory Aid
Information ยท Systems ยท Devices ยท Facilities ยท Applications ยท Services
The Access Architect's Questions
Key Takeaways
Access control determines which subjects may reach organisational assets and what actions they may perform.
CISSP 5.1 applies access control to information, systems, devices, facilities, applications and services.
Physical access controls where people can physically go and which equipment they can reach.
Logical access controls which digital resources an identity can use.
Physical and logical controls should complement rather than replace each other.
A subject is an active entity requesting access, while an object is a resource being accessed.
Access control applies to users, processes, applications, services and devices - not just human accounts.
Identification establishes the claimed identity, authentication verifies it, and authorisation determines what the authenticated identity may do.
Successful authentication does not imply unlimited authorisation.
Least privilege grants only the capabilities necessary to perform the legitimate task.
Need-to-know focuses on whether access to specific information is genuinely required.
Default-deny design begins with no access and explicitly permits legitimate requirements.
Information controls may restrict access at file, database, record and application levels.
Encryption protects information but does not replace logical access control.
Systems frequently provide multiple access paths including local login, remote access, APIs, service accounts, management interfaces and physical consoles.
Security should identify and protect every viable access path rather than only the primary user interface.
Privileged administrative access deserves stronger controls because it can alter systems, identities, permissions and security policy.
Separating everyday user accounts from privileged administrative identities reduces unnecessary exposure of high-value credentials.
User trust and device trust are separate decisions.
Physical access should also follow least privilege, with increasingly restricted areas surrounding more sensitive assets.
Tailgating can bypass individual physical authentication when an unauthorised person follows an authorised person into a restricted area.
Application access is not binary. Controls can restrict individual functions, records and actions after a user enters the application.
Services, APIs and machine identities should receive only the access required to perform their function.
Non-human identities can create significant risk through excessive permissions, long-lived credentials and unclear ownership.
Separation of duties divides sensitive responsibilities between multiple people or roles.
Dual control requires two authorised parties to participate in a sensitive activity.
Context-aware controls can consider identity, device, location, network, authentication strength and other signals when determining access.
Temporary business requirements do not necessarily justify permanent standing privilege.
Access logging supports accountability by recording who accessed which resource, when, from where and what action was performed.
Shared accounts weaken accountability because actions become more difficult to attribute to specific individuals.
Access reviews help identify privilege accumulation, obsolete access, inactive accounts and permissions that no longer match current duties.
Access has a lifecycle: request, approve, provision, use, review, modify and revoke.
Access should follow the current business requirement - not the user's historical collection of permissions.
The overall CISSP principle is to give the right subject access to the right asset, for the right purpose, with only the required permissions, under appropriate conditions and only for as long as the access is needed.
๐ Sources & Further Reading Identity, physical access and logical access references
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations
View NIST security and privacy controls - NIST CSRC - Logical Access Control System
View the NIST logical access-control definition - NIST SP 800-207 - Zero Trust Architecture
View NIST Zero Trust Architecture
