2

Specifically for the CISSP, trying to figure out what type of access control these would be considered.

cpast
  • 7,223
  • 1
  • 29
  • 35
gorgon112
  • 21
  • 2

2 Answers2

1

Short answer: Both smart cards and firewalls would be considered technical access controls.

There are three types of access control as defined by ISC2, technical, administrative, and physical. Physical includes badge readers, physical locks, etc. Administrative would be policies or procedures about access. Technical includes hardware or software systems which provide access control.

theterribletrivium
  • 2,679
  • 17
  • 18
-1

The above is correct, but my understanding is that they could also could be considered a physical control. "If you can hit your head on it, or drop it on your foot, it's a physical control". If you have an actual rack mounted firewall, for example, that device is a physical control. The software inside would be a technical control.

Obscure
  • 11
  • 2