SkarpSkarp

Chapter 5 of 5

Controlling Access, Assets and the Physical Operating Environment

The Regulation closes the control chain by asking who can reach systems, what assets must be protected and whether facilities can withstand disruption. This final chapter consolidates the document through identity and privileged-access safeguards, traceable asset lifecycles, utility resilience, security perimeters and continuous physical monitoring.

21 min readen

1. The Control Chain: Access, Assets, and Facilities

Three connected control areas

Points 11 to 13 of Commission Implementing Regulation (EU) 2024/2690 connect access control, asset management, and environmental and physical security.

A control chain

`Identity -> Access right -> System or asset -> Facility and supporting utilities`\n\nEach link matters: failure in one can weaken the protection delivered by the others.

Read qualifiers carefully

The Regulation uses mandatory shall requirements. Some detailed measures apply where appropriate; that condition remains part of the requirement.

2. Access Control Policy and Access Rights

Policy comes first

Point 11.1.1 requires logical and physical access-control policies, based on business requirements and network and information system security requirements.

Who and what must the policy cover?

The policy must address people such as staff, visitors, suppliers, and service providers; access by systems; and authentication before access is granted.

Three access principles

Access rights must be assigned and revoked using need-to-know, least privilege, and separation of duties.

Third parties are bounded

Third-party access must be addressed, particularly by limiting access rights in scope and in duration. Granted rights need a register and logging.

3. Applying Access Rights in Practice

Temporary supplier access

A supplier may need access for a diagnosis, but point 11.2.2(d) requires third-party access to be limited in scope and duration.

Control flow

Authorise the access, give only the needed system reach, set an end point, record the right, and apply logging to its management.

Physical analogy

Think of a badge that opens one room during one maintenance window and records each use. Digital third-party access should be similarly bounded.

Knowledge Check: Third-Party Access

Choose the action that most directly reflects point 11.2.2(d).

A service provider needs access to repair a specific system for one evening. Which approach best matches the Regulation?

  1. Grant a permanent administrator account so future repairs are faster.
  2. Grant authorised access limited to the relevant system and the approved time period.
  3. Allow access without recording it because the provider is under contract.
  4. Give the provider the same access rights as internal system administrators.
Show Answer

Answer: B) Grant authorised access limited to the relevant system and the approved time period.

Point 11.2.2(d) requires third-party access rights to be appropriately addressed, in particular by limiting access rights in scope and in duration. Other requirements include authorisation, a register of granted rights, and logging to the management of access rights.

4. Privileged Accounts, Administration Systems, and Identities

Privileged access is distinct

Policies for privileged and system administration accounts are part of the access-control policy, but they carry specific identification, authentication, authorisation, and use restrictions.

Use dedicated administrator accounts

Specific accounts must be used exclusively for system administration operations. Privileges must be individualised and restricted to the highest extent possible.

Administration systems have one purpose

Administration systems must be used only for administration, logically separated from unrelated application software, and protected through authentication and encryption.

Shared identities are exceptional

Shared identities are permitted only where necessary for business or operational reasons and subject to an explicit approval process and documentation.

5. Authentication and Multi-Factor Authentication

Authentication follows classification

Authentication strength must be appropriate to the classification of the asset being accessed. The same principle appears in points 11.6 and 11.7.

Credential and session controls

The Regulation requires initial, periodic, and compromise-triggered credential changes; predefined failed-login blocking; and inactive-session termination after a predefined period.

Separate privileged credentials

Users need separate credentials to access privileged or administrative accounts. This separates ordinary use from elevated access.

MFA is qualified

Multiple authentication factors or continuous authentication mechanisms are required where appropriate, according to the classification of the asset to be accessed.

6. Flashcards: Identity and Access Terms

Flip each card, then explain how the term affects a real access decision.

Need-to-know
An access-right principle required by point 11.2.2(a). Rights are assigned and revoked based on the information or system access needed for the relevant role or task.
Least privilege
An access-right principle required by point 11.2.2(a). Access should not exceed what is needed for the authorised purpose.
Separation of duties
An access-right principle required by point 11.2.2(a). Duties and access should be arranged so that incompatible actions are not concentrated without appropriate separation.
Shared identity
An identity assigned to multiple persons. Point 11.5.3 permits it only where necessary for business or operational reasons and subject to explicit approval and documentation.
System administration account
A specific account used exclusively for system administration operations. It must only be used to connect to system administration systems.
Continuous authentication mechanism
An alternative to multiple authentication factors in point 11.7.1, where appropriate and in accordance with the classification of the asset to be accessed.

7. Asset Classification and Asset Handling

Classify every in-scope asset

Point 12.1.1 requires classification levels for all assets, including information, in scope of network and information systems.

Four classification inputs

Classification is based on confidentiality, integrity, authenticity, and availability requirements, indicating needed protection by sensitivity, criticality, risk, and business value.

Availability must align

Asset availability requirements must align with delivery and recovery objectives in business continuity and disaster recovery plans.

Handling is life-cycle wide

The handling policy covers acquisition, use, storage, transportation, and disposal, plus safe transfer and irretrievable deletion or destruction.

8. Removable Media, Inventory, and Offboarding Assets

Default: technically prohibit removable media

Connection of removable media must be technically prohibited unless an organisational reason exists for its use. The policy also covers scanning and disabling self-execution.

Inventory is not a one-time list

The inventory must be complete, accurate, up-to-date, and consistent. Entry changes must be traceable, and the history of changes documented.

Termination procedures

Assets under personnel custody must be deposited, returned, or deleted upon termination, with documentation of the outcome.

If recovery is impossible

Where deposit, return, or deletion is not possible, the asset must no longer be able to access the entity's network and information systems.

9. Supporting Utilities and Environmental Threats

Utilities are cybersecurity dependencies

Point 13.1.1 addresses loss, damage, compromise, or operational interruption caused by failure or disruption of supporting utilities.

Where appropriate: resilience measures

Relevant entities may need protection against failures in electricity, telecoms, water, gas, sewage, ventilation, and air conditioning, and must consider utility-service redundancy.

Thresholds create action points

Relevant entities must, where appropriate, determine minimum and maximum control thresholds for physical and environmental threats and report events outside them.

Risk assessment matters

Protection against physical and environmental threats is based on the risk assessment under point 2.1, then tested, reviewed, and updated on the stated basis.

10. Final Check: Physical Perimeters and Monitoring

Apply point 13.3 Perimeter and physical access control to the situation below.

Which set of measures most closely reflects point 13.3.2 for a room containing network and information systems?

  1. Use security perimeters based on the point 2.1 risk assessment, appropriate entry controls and access points, physical security for the facility, and continuous monitoring for unauthorised physical access.
  2. Install one lock on the building's main entrance and inspect it only after a significant incident.
  3. Rely on employee awareness because physical controls are outside cybersecurity risk management.
  4. Monitor environmental parameters but do not control entry to rooms containing network and information systems.
Show Answer

Answer: A) Use security perimeters based on the point 2.1 risk assessment, appropriate entry controls and access points, physical security for the facility, and continuous monitoring for unauthorised physical access.

Point 13.3.1 requires relevant entities to prevent and monitor unauthorised physical access, damage, and interference. Point 13.3.2 requires security perimeters based on the point 2.1 risk assessment, appropriate entry controls and access points, physical security for offices, rooms, and facilities, and that entities "continuously monitor their premises for unauthorised physical access".

Key Terms

Need-to-know
A principle under point 11.2.2(a) for assigning and revoking access rights.
Asset inventory
The complete, accurate, up-to-date, and consistent inventory of assets required by point 12.4, with traceable changes and documented history.
Least privilege
A principle under point 11.2.2(a) for assigning and revoking access rights.
Shared identity
An identity assigned to multiple persons; point 11.5.3 permits it only when necessary for business or operational reasons and subject to explicit approval and documentation.
Control thresholds
Minimum and maximum thresholds for physical and environmental threats, used for monitoring and reporting events outside those thresholds.
Privileged account
An account covered by the specific management-policy, identification, authentication, authorisation, review, and documentation requirements in point 11.3.
Security perimeter
A perimeter laid down and used under point 13.3.2(a) to protect areas where network and information systems and associated assets are located.
Asset classification
The system of classification levels for assets, including information, based on confidentiality, integrity, authenticity, availability, sensitivity, criticality, risk, and business value.
Separation of duties
A principle under point 11.2.2(a) for assigning and revoking access rights.
Supporting utilities
Utilities whose failure or disruption can cause loss, damage, compromise, or operational interruption, including examples such as electricity and telecommunications.
Access control policy
The logical and physical access-control policy required by point 11.1 for access to network and information systems, based on business and security requirements.
System administration account
A specific account used exclusively for system administration operations and only to connect to system administration systems.
Continuous authentication mechanism
A mechanism that may authenticate users under point 11.7.1 as an alternative to multiple authentication factors, where appropriate and according to asset classification.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself