Domain 3 – Access Control
Concepts
3.1: Access Control Concepts
3.2: Physical access controls
3.3: Logical access controls
Waleed Elnaggar
https://www.youtube.com/naggaracademy
Security Controls
https://www.youtube.com/naggaracademy
Security controls are countermeasures or safeguards used to reduce the chances that a
threat will exploit a vulnerability
Subjects & Objects
https://www.youtube.com/naggaracademy
 A subject is an entity that requires access to system
resources (human, batch job, application, etc.)
 An object is a resource to which access must be
controlled
 An access control rule specifies the rights of a
different types of subjects (user, group, role, or
organization) to access objects
Defense in Depth
https://www.youtube.com/naggaracademy
Defense in depth is a strategy that leverages
multiple security measures to protect an
organization's assets. The thinking is that if
one line of defense is compromised,
additional layers exist as a backup to ensure
that threats are stopped along the way.
Least Privilege
https://www.youtube.com/naggaracademy
The principle of least privilege is a security
concept in which a user is given the minimum
levels of access or permissions needed to
perform their job
Need to Know
https://www.youtube.com/naggaracademy
Access to data should only be granted when
it is necessary to fulfill specific tasks or
responsibilities.
Privileged Access Management (PAM)
https://www.youtube.com/naggaracademy
An identity security solution that helps protect
organizations against cyber-threats by
monitoring, detecting, and preventing
unauthorized privileged access to critical
resources
Segregation of Duties
https://www.youtube.com/naggaracademy
The concept of having more than one person
required to complete a task.
An administrative control used by organizations to
prevent fraud, sabotage, theft, misuse of information,
and other security compromises.
Collusion occurs when people
responsible for different aspects of a
segregated process decide to come
together to deliberately override the
controls for their own benefit
Provisioning
https://www.youtube.com/naggaracademy
https://www.youtube.com/naggaracademy

CC 3-1 Access Control Concepts.pdf