Chapter 5 of 5
Controlling Access, Assets and the Physical Operating Environment
The Regulation closes the control chain by asking who can reach systems, what assets must be protected and whether facilities can withstand disruption. This final chapter consolidates the document through identity and privileged-access safeguards, traceable asset lifecycles, utility resilience, security perimeters and continuous physical monitoring.
1. The Control Chain: Access, Assets, and Facilities
Three connected control areas
Points 11 to 13 of Commission Implementing Regulation (EU) 2024/2690 connect access control, asset management, and environmental and physical security.
A control chain
`Identity -> Access right -> System or asset -> Facility and supporting utilities`\n\nEach link matters: failure in one can weaken the protection delivered by the others.
Read qualifiers carefully
The Regulation uses mandatory shall requirements. Some detailed measures apply where appropriate; that condition remains part of the requirement.
2. Access Control Policy and Access Rights
Policy comes first
Point 11.1.1 requires logical and physical access-control policies, based on business requirements and network and information system security requirements.
Who and what must the policy cover?
The policy must address people such as staff, visitors, suppliers, and service providers; access by systems; and authentication before access is granted.
Three access principles
Access rights must be assigned and revoked using need-to-know, least privilege, and separation of duties.
Third parties are bounded
Third-party access must be addressed, particularly by limiting access rights in scope and in duration. Granted rights need a register and logging.
3. Applying Access Rights in Practice
Temporary supplier access
A supplier may need access for a diagnosis, but point 11.2.2(d) requires third-party access to be limited in scope and duration.
Control flow
Authorise the access, give only the needed system reach, set an end point, record the right, and apply logging to its management.
Physical analogy
Think of a badge that opens one room during one maintenance window and records each use. Digital third-party access should be similarly bounded.
Knowledge Check: Third-Party Access
Choose the action that most directly reflects point 11.2.2(d).
A service provider needs access to repair a specific system for one evening. Which approach best matches the Regulation?
- Grant a permanent administrator account so future repairs are faster.
- Grant authorised access limited to the relevant system and the approved time period.
- Allow access without recording it because the provider is under contract.
- Give the provider the same access rights as internal system administrators.
Show Answer
Answer: B) Grant authorised access limited to the relevant system and the approved time period.
Point 11.2.2(d) requires third-party access rights to be appropriately addressed, in particular by limiting access rights in scope and in duration. Other requirements include authorisation, a register of granted rights, and logging to the management of access rights.
4. Privileged Accounts, Administration Systems, and Identities
Privileged access is distinct
Policies for privileged and system administration accounts are part of the access-control policy, but they carry specific identification, authentication, authorisation, and use restrictions.
Use dedicated administrator accounts
Specific accounts must be used exclusively for system administration operations. Privileges must be individualised and restricted to the highest extent possible.
Administration systems have one purpose
Administration systems must be used only for administration, logically separated from unrelated application software, and protected through authentication and encryption.
Shared identities are exceptional
Shared identities are permitted only where necessary for business or operational reasons and subject to an explicit approval process and documentation.
5. Authentication and Multi-Factor Authentication
Authentication follows classification
Authentication strength must be appropriate to the classification of the asset being accessed. The same principle appears in points 11.6 and 11.7.
Credential and session controls
The Regulation requires initial, periodic, and compromise-triggered credential changes; predefined failed-login blocking; and inactive-session termination after a predefined period.
Separate privileged credentials
Users need separate credentials to access privileged or administrative accounts. This separates ordinary use from elevated access.
MFA is qualified
Multiple authentication factors or continuous authentication mechanisms are required where appropriate, according to the classification of the asset to be accessed.
6. Flashcards: Identity and Access Terms
Flip each card, then explain how the term affects a real access decision.
- Need-to-know
- An access-right principle required by point 11.2.2(a). Rights are assigned and revoked based on the information or system access needed for the relevant role or task.
- Least privilege
- An access-right principle required by point 11.2.2(a). Access should not exceed what is needed for the authorised purpose.
- Separation of duties
- An access-right principle required by point 11.2.2(a). Duties and access should be arranged so that incompatible actions are not concentrated without appropriate separation.
- Shared identity
- An identity assigned to multiple persons. Point 11.5.3 permits it only where necessary for business or operational reasons and subject to explicit approval and documentation.
- System administration account
- A specific account used exclusively for system administration operations. It must only be used to connect to system administration systems.
- Continuous authentication mechanism
- An alternative to multiple authentication factors in point 11.7.1, where appropriate and in accordance with the classification of the asset to be accessed.
7. Asset Classification and Asset Handling
Classify every in-scope asset
Point 12.1.1 requires classification levels for all assets, including information, in scope of network and information systems.
Four classification inputs
Classification is based on confidentiality, integrity, authenticity, and availability requirements, indicating needed protection by sensitivity, criticality, risk, and business value.
Availability must align
Asset availability requirements must align with delivery and recovery objectives in business continuity and disaster recovery plans.
Handling is life-cycle wide
The handling policy covers acquisition, use, storage, transportation, and disposal, plus safe transfer and irretrievable deletion or destruction.
8. Removable Media, Inventory, and Offboarding Assets
Default: technically prohibit removable media
Connection of removable media must be technically prohibited unless an organisational reason exists for its use. The policy also covers scanning and disabling self-execution.
Inventory is not a one-time list
The inventory must be complete, accurate, up-to-date, and consistent. Entry changes must be traceable, and the history of changes documented.
Termination procedures
Assets under personnel custody must be deposited, returned, or deleted upon termination, with documentation of the outcome.
If recovery is impossible
Where deposit, return, or deletion is not possible, the asset must no longer be able to access the entity's network and information systems.
9. Supporting Utilities and Environmental Threats
Utilities are cybersecurity dependencies
Point 13.1.1 addresses loss, damage, compromise, or operational interruption caused by failure or disruption of supporting utilities.
Where appropriate: resilience measures
Relevant entities may need protection against failures in electricity, telecoms, water, gas, sewage, ventilation, and air conditioning, and must consider utility-service redundancy.
Thresholds create action points
Relevant entities must, where appropriate, determine minimum and maximum control thresholds for physical and environmental threats and report events outside them.
Risk assessment matters
Protection against physical and environmental threats is based on the risk assessment under point 2.1, then tested, reviewed, and updated on the stated basis.
10. Final Check: Physical Perimeters and Monitoring
Apply point 13.3 Perimeter and physical access control to the situation below.
Which set of measures most closely reflects point 13.3.2 for a room containing network and information systems?
- Use security perimeters based on the point 2.1 risk assessment, appropriate entry controls and access points, physical security for the facility, and continuous monitoring for unauthorised physical access.
- Install one lock on the building's main entrance and inspect it only after a significant incident.
- Rely on employee awareness because physical controls are outside cybersecurity risk management.
- Monitor environmental parameters but do not control entry to rooms containing network and information systems.
Show Answer
Answer: A) Use security perimeters based on the point 2.1 risk assessment, appropriate entry controls and access points, physical security for the facility, and continuous monitoring for unauthorised physical access.
Point 13.3.1 requires relevant entities to prevent and monitor unauthorised physical access, damage, and interference. Point 13.3.2 requires security perimeters based on the point 2.1 risk assessment, appropriate entry controls and access points, physical security for offices, rooms, and facilities, and that entities "continuously monitor their premises for unauthorised physical access".
Key Terms
- Need-to-know
- A principle under point 11.2.2(a) for assigning and revoking access rights.
- Asset inventory
- The complete, accurate, up-to-date, and consistent inventory of assets required by point 12.4, with traceable changes and documented history.
- Least privilege
- A principle under point 11.2.2(a) for assigning and revoking access rights.
- Shared identity
- An identity assigned to multiple persons; point 11.5.3 permits it only when necessary for business or operational reasons and subject to explicit approval and documentation.
- Control thresholds
- Minimum and maximum thresholds for physical and environmental threats, used for monitoring and reporting events outside those thresholds.
- Privileged account
- An account covered by the specific management-policy, identification, authentication, authorisation, review, and documentation requirements in point 11.3.
- Security perimeter
- A perimeter laid down and used under point 13.3.2(a) to protect areas where network and information systems and associated assets are located.
- Asset classification
- The system of classification levels for assets, including information, based on confidentiality, integrity, authenticity, availability, sensitivity, criticality, risk, and business value.
- Separation of duties
- A principle under point 11.2.2(a) for assigning and revoking access rights.
- Supporting utilities
- Utilities whose failure or disruption can cause loss, damage, compromise, or operational interruption, including examples such as electricity and telecommunications.
- Access control policy
- The logical and physical access-control policy required by point 11.1 for access to network and information systems, based on business and security requirements.
- System administration account
- A specific account used exclusively for system administration operations and only to connect to system administration systems.
- Continuous authentication mechanism
- A mechanism that may authenticate users under point 11.7.1 as an alternative to multiple authentication factors, where appropriate and according to asset classification.