Logical Access Control Systems

Logical access control systems manage user permissions within operating systems, applications, and networks, often combining built-in features and add-on security solutions.

5 slides · 2 min read · Domain 5

Slide 1

The Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance provides a framework for U.S. federal agencies to manage enterprise ICAM (Identity, Credential, and Access Management).

Logical access controls are authorized systems that authorize or deny user access based on verified identity.

These controls are an important part of FICAM and are essential to strengthening federal cybersecurity posture.

According to the FICAM Roadmap, these systems:

  • Authorize or deny access to individual users.
  • Operate based on identities registered and approved by the system.
  • Control access to information system resources such as endpoints, networks, applications, and data.
  • Grant access by applying the permissions associated with the user's approved identity.

FICAM and related sources (e.g., NIST SP 800-63) offer guidance that aligns with tasks commonly associated with the stages in the identity management life cycle.

Some interpretations or discussions around FICAM can blur two distinct tasks: identification management and access control. As many of us know from personal experience, although we are one unique individual, we have multiple digital identities, some of which may be accepted for authentication by certain systems but not by others. Those systems then undertake the separate but equally vital tasks of authorizing our attempts to access resources.

Due to the large number of remote users, many system environments require more complex and nuanced logical access control systems than those needed for physical access control. For example, as the smart card entryway illustrates, both types of systems must collaborate to achieve effective overall security. However, it is generally simpler, in principle, to restrict the physical movement and actions of individuals than to control the many forms of remote access, shared resource usage, and collaborative environments.

Many logical access controls are built into the operating system or designed as features of application platforms or major utilities, such as database management systems (DBMSs).

They may also be implemented through add-on security packages installed on the operating system. Such packages are available for various systems, including PCs and mainframes. Additionally, logical access controls may exist in specialized components that regulate communications between computers and networks.

Test this domain