Glossary

Logical Access Security

Technical measures such as passwords and multi-factor authentication for system access.

A

B

C

D

E

F

G

H

I

J

K

L

Logical access security refers to the technical controls that regulate who can access information systems, applications, and data. These controls include authentication mechanisms such as passwords, multi-factor authentication, biometric verification, and certificate-based authentication, as well as authorisation controls that determine what authenticated users are permitted to do within a system.

A robust logical access security framework is foundational to compliance with virtually every information security standard, including ISO 27001, SOC 2, and NIS2. It involves implementing strong password policies, enforcing session timeouts, maintaining access control lists, and conducting regular access reviews to ensure that permissions remain aligned with the principle of least privilege.

M

N

O

P

Q

R

S

T

U

V

W

Z

Frequently asked questions

What is logical access control?
Logical access control is the use of technical measures, such as authentication, authorisation and access rights, to restrict who can access systems, applications and data.
What is the difference between logical and physical access control?
Physical access control restricts entry to physical locations such as doors and server rooms, while logical access control restricts access to digital systems and data.
Why does logical access control matter for ISO 27001?
Access control is a core requirement of ISO 27001 (Annex A); logical controls such as least-privilege access and multi-factor authentication are key measures for protecting information.