Logical access control
Access control enforced electronically by hardware or software, such as authentication, permissions, access control lists and network rules, as opposed to physical barriers.
Logical access control governs electronic access to an asset. Where a physical control stops a person reaching a room or a device, a logical control decides whether a subject can log in, read a file, call an interface or reach a network segment. Typical examples are login prompts and multi-factor authentication, file and database permissions, access control lists, firewall and network rules, and encryption. The ISC2 outline’s first Domain 5 objective is to “Control physical and logical access to assets”, naming information, systems, devices, facilities, applications and services.
Logical controls are also called technical controls, one of the three implementation types commonly set out in control types alongside administrative and physical controls. They are distinct from physical access control, though the two often work together: a badge system is a physical control driven by logical decisions about which badge opens which door, and a server in an unlocked room can have its logical controls bypassed by someone who removes the disk. Logical access decisions follow the organisation’s access control model.
Exam relevance: a scenario is likely to list several controls and ask which are logical. Candidates are expected to classify by how the control is enforced (software or hardware logic, not a lock or a guard) and to recognise that physical access can defeat logical controls.