Logical Access Controls for IS Auditors
User IDs, roles and permissions are the IT version of the authorisation matrix. Here's how to test them.
Logical access controls are the software rules that decide who can use a system and what they can do in it: user IDs, passwords, roles, permissions and the logs that record their use. For a CA they are the IT version of the authorisation matrix, and they underpin almost every reliance an auditor places on an ERP.
DISA Module 5 covers access paths, attacks, access-control mechanisms, identity and access management (IAM), single sign-on and audit trails. NIST's Cybersecurity Framework 2.0 groups the same outcomes under Protect as identity management, authentication and access control.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The Four Steps of Access, and the Models
- Identification
- Claiming an identity, usually by entering a user ID. Says who you claim to be, proves nothing.
- Authentication
- Proving that claim with a factor: something you know (password), something you have (token, phone OTP) or something you are (biometric).
- Authorisation
- What the authenticated user is allowed to do: which transactions, screens and data.
- Accountability
- Logging actions against a unique user so they can be traced. Shared IDs destroy accountability.
- Multi-factor authentication (MFA)
- Two or more factors of different types. A password plus a PIN is two items of the same type, so it is not MFA.
- Role-based access control (RBAC)
- Rights attached to job roles, and users assigned to roles. The usual ERP model.
- Discretionary access control (DAC)
- The data owner decides who gets access, as with shared folders.
- Mandatory access control (MAC)
- Access set by the system from classification labels on data and clearances on users; owners can't override it.
- Least privilege
- Each user gets only the access the job needs, nothing more.
Testing a User Access Review: SAP Example
A mid-size manufacturer runs SAP. Management says access is reviewed every quarter.
- 1
Get the population from the system
Extract users, roles and last-logon dates from SAP itself, not a spreadsheet maintained by IT.
- 2
Check joiners
Sample new users; match each to an approved access request with the role the manager signed off.
- 3
Check leavers
Match HR's exit list to the user list. Any active ID for someone who has left, and any logon after the exit date, is an exception.
- 4
Check movers
Staff who changed departments often keep old roles. Look for access accumulated across jobs.
- 5
Run a segregation-of-duties analysis
Flag users who can, for example, both create a vendor and post or release a payment to that vendor.
- 6
Test the review itself
Did reviewers act on what they found? A signed review that removed nothing, when exceptions exist, is evidence the control did not operate.
- 7
Look at privileged and generic IDs
Superuser and firefighter (emergency) IDs should be named, time-bound, logged and reviewed by someone independent.
Quick practice on audit concepts. No signup.
Common Attacks on Access Controls
- check_circlePassword guessing and brute force, answered by lockout after failed attempts and MFA
- check_circlePhishing for credentials, answered by MFA and awareness training
- check_circlePrivilege escalation: a normal user gaining administrator rights through a flaw or misconfiguration
- check_circlePiggybacking on an unattended logged-in session, answered by automatic session time-outs
- check_circleDormant accounts of former staff or vendors used as a back door
How the DISA Assessment Test Tests This
Expect questions that test the precise vocabulary: identification versus authentication, what counts as MFA, which model a scenario describes. The trap is reading "user enters a user ID and password" as two factors. It is identification plus one factor.
Scenario questions usually ask for the most effective control or the auditor's biggest concern. Active IDs of former employees, shared administrator passwords and SoD conflicts in payments are the high-risk findings; an expired password policy setting is a lesser one.
FAQs
What is the difference between identification and authentication?expand_more
Identification is claiming who you are, usually with a user ID. Authentication is proving it with a password, token or biometric.
Is a password plus a security question multi-factor authentication?expand_more
No. Both are something you know. MFA needs factors from different categories, such as a password plus an OTP on a registered phone.
What is the difference between RBAC, DAC and MAC?expand_more
RBAC assigns rights by job role, DAC lets the data owner grant access, and MAC enforces access from classification labels that owners cannot change.
What is a segregation of duties conflict in an ERP?expand_more
A user who holds two roles that should be separate, so one person can complete a sensitive process alone, for example creating a vendor and releasing a payment to it.
Next steps
- Network Securityarrow_forward
- Physical Controlsarrow_forward
- ERP Auditarrow_forward
- Database Controlsarrow_forward
Assessment Test format, timed and scored.
