Section 2: 35–45%I7
Logical and Physical Access Controls
Exam insight
Access controls are the most heavily tested area of ISC because they enforce confidentiality and integrity at the gate. You must be able to distinguish authentication from authorization, name the access control models, and recognize the right physical, network, and cryptographic control for a given goal.
What AICPA wants you to know
- 1Distinguish the three authentication factors and explain what makes authentication multi-factor.
- 2Separate authentication (who you are) from authorization (what you may do).
- 3Compare the RBAC, MAC, and DAC access control models.
- 4Describe user provisioning, deprovisioning, periodic access reviews, and privileged access management.
- 5Identify appropriate physical and network controls for a stated objective.
- 6Compare symmetric and asymmetric encryption, hashing, and PKI, and contrast data at rest with data in transit.
Patterns in this topic
The exam re-skins the same archetypes. Recognize these here, then drill them in the Pattern Lab.
Exam tip
Study smarter: before you expand each card, cover the screen and try to recall what the concept means from its title alone. Retrieving it from memory builds the recall the exam actually tests, and it beats re-reading.