Access controls enable the protection of security assets by restricting access to systems and data by users, applications and other systems. Without a doubt, access controls are the cornerstone of any enterprise information security program.
Requires Free Membership to View
SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!
Michael S. Mimoso, Editorial DirectorIn this CISSP Essentials Security School lesson, Domain 2, Access Control, expert CISSP exam trainer Shon Harris offers a video presentation detailing how access controls support the core security principles of confidentiality, integrity and availability by inducing subjects to positively identify themselves, verify they possess appropriate credentials and the necessary rights and privileges to obtain access to the target resource and its information. Key focus areas include access control principles; administration and practices; models and technologies; types, methods and techniques; and threat monitoring.
Prepare for the video by reading the Domain 2 spotlight article, which provides an in-depth look at the challenges and principles behind access controls, their diverse variety, what threats they can mitigate and the challenges of selecting, implementing and administering them.
After watching the video, test your comprehension of this material with our Domain 2, Access Control quiz. Upon completion, return to the CISSP Essentials Security School table of contents to select your next lesson.
About the instructor:
Shon
Harris is a CISSP, MCSE and President of Logical Security, a firm specializing in security
educational and training tools. Logical Security offers curriculum, virtual labs, instructor slides
and tools for lease by training companies, security companies, military organizations, government
sectors and corporations.
Shon is also a security consultant, an engineer in the Air Force's Information Warfare unit, an entrepreneur and an author. She has authored two best selling CISSP books, including CISSP All-in-One Exam Guide, and was a contributing author to the book Hacker's Challenge. Shon is currently finishing her newest book, Gray Hat Hacking: The Ethical Hacker's Handbook.
CISSP is a registered certification mark of the International Information Systems Security Certification Consortium, Inc., also known as (ISC)2.
This was first published in July 2008
Security Management Strategies for the CIO