Access control
Access control is a set of rules and tools that determine who and under what conditions can gain access to resources: data, premises, systems.
What is access control in simple words
Access control is a set of rules, methods and technologies that determine who is allowed to enter physical territory or use information resources. In simple words, it is a system that answers the questions: "Who are you?", "Confirm that it is you" and "What are you allowed to do?".
Imagine an ordinary office: at the entrance there is a security guard who checks passes. This is physical access control. In the digital world, everything is the same: when you enter a login and password to access a system, you undergo digital access control. Without this system, anyone could get into your account or your premises, and security would be at risk.
Access control is a fundamental mechanism for ensuring information security along with identification, authentication and audit. These processes are closely related: first the system identifies the user (determines who they are), then authenticates them (checks authenticity), and only after that authorizes them (allows or denies access to specific resources).
Effective access control allows preventing unauthorized access to information, protecting critical resources and ensuring compliance with regulator requirements. Without access control, a modern corporate IT infrastructure or a physical security system is impossible to imagine.
Access control models
- Discretionary access control (DAC): The owner of a resource assigns access rights themselves. This is the most flexible model, but it requires the active participation of the owner in rights management. Used in small organizations and in systems with low security requirements.
- Mandatory access control (MAC): Access based on security labels assigned to objects and subjects. Used in government systems and systems with high security requirements, where a strict hierarchy of access levels is necessary.
- Role-based access control (RBAC): Rights are assigned to roles, not to individual users. This is the most common model in corporate systems, as it simplifies access management in large organizations. For example, the roles "Accountant" and "Manager" have different rights in the system.
- Attribute-based access control (ABAC): Access based on the attributes of the subject, object, action and environment. This is the most flexible and modern model, allowing the creation of complex access rules. For example, access can be allowed only during working hours, from a corporate device and from the office network.
The choice of model depends on security requirements, system architecture and organization size. Large government systems often use combined approaches, for example, RBAC with elements of ABAC for more flexible access management.
In addition, there are specialized models, such as granular access (access at the level of individual records or fields) and dynamic access (rights can change depending on the current situation). The choice of a specific model should be based on a thorough analysis of threats and security requirements.
Implementation tools
- Software tools: Active Directory, LDAP (Lightweight Directory Access Protocol), identity and access management systems (IAM). They allow centralized management of accounts and access rights.
- Hardware tools: access control systems (ACS), controllers, readers. They provide physical access control at facilities.
- Biometric systems: Biomark (fingerprints), Biovizum (face recognition). They provide a high level of security, since biometric characteristics cannot be forged or transferred to another person.
- Workstations for document verification: ARM-1, ARM-2, used at checkpoints and in identity verification systems.
These tools can work separately or together, forming a unified access control system. For example, a large organization may use Active Directory for digital access control and an ACS with biometrics for physical access control to premises at the same time.
The design service includes the choice of a model, development of policies and integration of all components into a unified system. This is a complex task requiring consideration of many factors: from security requirements to budget and architecture of the existing IT infrastructure. Read more about approaches in the technologies section.
Frequently asked questions
What is access control?
Access control is a set of rules, methods and technologies that determine who is allowed to enter physical territory or use information resources. It is divided into physical (ACS) and digital (access to data and systems). It is based on identification, authentication and authorization. The Biomark biometric systems provide reliable identification. The design service will help implement access control.
What types of access control systems are there?
Access control systems are divided by architecture: standalone (for one door), networked (managed from a central server) and wireless. By identification method: electronic (cards, key fobs), biometric (fingerprints, face) and mobile (smartphone). Large organizations use the role-based model (RBAC). The Biomark biometric systems provide a high level of security. The design service will help you choose the optimal system.
What is an access control system?
An access control system (ACS) is a set of software and hardware tools that automatically determines who is allowed entry. It consists of identifiers (cards, biometrics), readers, controllers (the "brain" of the system) and locking devices (locks, turnstiles). Main functions: entry restriction, working time tracking and security. The Biomark and Biovizum products integrate with ACS. The design service will help implement the system.
What is an access controller?
An access controller is the "brain" of an access control system (ACS). It receives a signal from the reader, checks it against the database and decides whether to open the lock or deny access. Controllers are standalone (for one point) and networked (managed centrally). Integration with the Biomark biometric systems increases security. The design service will help you select and configure controllers.
Why is access control important?
Access control is important for limiting access to authorized users only, preventing data leaks and protecting critical resources. It ensures compliance with regulator requirements (for example, 152-FZ and 187-FZ) and is the basis of information security. The Biomark biometric systems provide a high level of identification. The design service will help implement effective access control.
What are the 5 principles of access control?
The five principles of access control: deterrence, detection, denial, delay and defense. These principles provide multi-level security: they deter attackers, detect intrusion attempts, block access, delay violators and protect resources. The Biomark biometric systems implement these principles in practice. The design service will help implement a comprehensive system.
What does an access control system include?
An access control system includes identifiers (cards, key fobs, biometric data), readers (scan the identifier), controllers (make a decision), actuators (locks, turnstiles) and software (rights management, time tracking). Modern ACS integrate with video surveillance and security alarms. The Biomark and Biovizum products provide biometric identification. The design service will help implement a comprehensive ACS.
Other terms in «Information Security»
Was this information helpful?
Protect your network today
Leave a request — our information security specialists will help you select, configure and integrate access control into your infrastructure. We will protect your data from threats.