Access Controls Concepts
Study ISC2 CC access control concepts: physical controls, monitoring, least privilege, separation of duties, DAC, MAC, and RBAC.
Access Controls Concepts is weighted at 22% in the current CC outline. It tests physical and logical access decisions, not just login terminology.
Work this domain in order
- Physical Access Controls for badges, guards, CCTV, alarms, logs, facility design, and authorized versus unauthorized personnel.
- Logical Access Controls for least privilege, separation of duties, DAC, MAC, RBAC, MFA, identity lifecycle, and automated service accounts.
Core distinction
| Question |
Concept |
| Who are you? |
identification |
| Can you prove it? |
authentication |
| What can you access? |
authorization |
| Can actions be traced? |
accountability |
Why access control matters
Many CC distractors solve only one part of access control. A password reset may help authentication, but it does not automatically solve authorization, logging, deprovisioning, or physical entry.
In this section
-
Physical Access Controls
Study ISC2 CC physical access controls: badges, gates, guards, CCTV, alarms, logs, facilities, and authorized personnel.
-
Logical Access Controls
Study ISC2 CC logical access controls: least privilege, separation of duties, DAC, MAC, RBAC, MFA, and identity lifecycle.
Revised on Monday, June 15, 2026