Security measures controlling who can access resources and what actions they can perform.
Access control encompasses all measures restricting access to resources—physical (locks, badges) and logical (permissions, authentication). Access control answers: who can access what, under what conditions, and what can they do? Effective access control implements least privilege, requires authentication, enforces authorisation, and maintains audit trails. Access control failures—excessive permissions, orphaned accounts, shared credentials—are common breach contributors.
Why It Matters
The DSC Perspective:
Access control is fundamental to security. If anyone can access anything, nothing is protected. Implement appropriate access controls across systems, review them regularly, and ensure they align with actual business needs.
