Access Controls Concepts

Study ISC2 CC access control concepts: physical controls, monitoring, least privilege, separation of duties, DAC, MAC, and RBAC.

Access Controls Concepts is weighted at 22% in the current CC outline. It tests physical and logical access decisions, not just login terminology.

Work this domain in order

  1. Physical Access Controls for badges, guards, CCTV, alarms, logs, facility design, and authorized versus unauthorized personnel.
  2. Logical Access Controls for least privilege, separation of duties, DAC, MAC, RBAC, MFA, identity lifecycle, and automated service accounts.

Core distinction

Question Concept
Who are you? identification
Can you prove it? authentication
What can you access? authorization
Can actions be traced? accountability

Why access control matters

Many CC distractors solve only one part of access control. A password reset may help authentication, but it does not automatically solve authorization, logging, deprovisioning, or physical entry.

In this section

  • Physical Access Controls
    Study ISC2 CC physical access controls: badges, gates, guards, CCTV, alarms, logs, facilities, and authorized personnel.
  • Logical Access Controls
    Study ISC2 CC logical access controls: least privilege, separation of duties, DAC, MAC, RBAC, MFA, and identity lifecycle.
Revised on Monday, June 15, 2026