Skip to content

Strategic Business Leader · IT systems security and control

Access Controls, Authentication and Encryption for ACCA SBL

Updated 11 October 2026 · Fact-checked

Access controls decide who can reach systems and data. Authentication proves a user's identity, using passwords, tokens or biometrics. Encryption scrambles data so it is unreadable without a key. In SBL, name the control, explain how it works, link it to the scenario's risk and state its limits.

Understand Access Controls, Authentication and Encryption

Start with the risk. A business holds valuable data: customer records, payment details, pricing, plans. Unauthorised people, inside or outside, may want to read, change or delete it. Security controls reduce that risk. This topic covers three groups: controls that decide who gets in, controls that check who they are, and controls that protect data even if someone gets past the first two.

Access controls limit what a person can reach. Physical access controls protect buildings, server rooms and devices, for example locks, badges and visitor logs. Logical access controls protect systems and data through software, for example login IDs, passwords and permissions. A firewall is a logical control that sits between networks, such as the company network and the internet. It filters traffic against rules and blocks what is not allowed.

Authentication proves a user is who they claim to be. There are three kinds of proof: something you know (password, PIN), something you have (phone, token, smart card) and something you are (fingerprint, face). Multi-factor authentication (MFA) needs two or more different kinds. A password plus a code sent to a phone is MFA. Two passwords is not, because both are the same kind. Passwords alone are weak because people reuse them, choose guessable ones or get tricked into revealing them.

Authorisation comes after authentication. It sets what a verified user may do. The principle of least privilege gives each user only the user rights needed for their job, for example read-only access to a ledger. Segregation of duties is supported by this: the person who raises a payment should not be able to approve it. Rights should be reviewed when staff change role or leave.

Encryption converts readable data (plaintext) into unreadable data (ciphertext) using an algorithm and a key. Only someone with the right key can decrypt it. It protects data in transit, such as online payments, and data at rest, such as laptops and databases. If a laptop is stolen, encrypted data stays unreadable. Encryption does not stop access to a system. It limits the damage when access controls fail. Its weakness is key management: lose the key and the data is lost, leak the key and the protection is gone.

Key rules to remember

Three authentication factors
Something you know + something you have + something you are
MFA needs at least two different factors. Two items from the same factor is not MFA.
Access control chain
Identification → Authentication → Authorisation → Accountability (logging)
Use this order to structure an answer. Logs let you trace who did what.
Encryption
Ciphertext = Encrypt(plaintext, key); Plaintext = Decrypt(ciphertext, key)
Symmetric encryption uses one shared key. Asymmetric uses a public key and a private key pair.
Least privilege
User rights = minimum needed to perform the role
Review rights on joining, role change and leaving.

How to solve Access Controls, Authentication and Encryption questions

Use this method for any SBL task on securing systems and data. It keeps your answer tied to the scenario, which earns both technical and professional skills marks.

  1. 1Read the requirement and identify the verb: identify, explain, evaluate or recommend. Match your depth to it.
  2. 2Pick out the scenario facts: what data is held, who uses it, where (remote, mobile, cloud), and any past incident.
  3. 3Identify the specific risk that follows, such as unauthorised access by staff, theft of a device or interception of data.
  4. 4Match each risk to a control: access control or firewall for entry, authentication for identity, user rights for what they can do, encryption for protecting the data itself.
  5. 5Explain how each control works in one or two sentences, then say how it solves this company's problem.
  6. 6Add limits and costs: user resistance, expense, key management, weak passwords, insider threat.
  7. 7Finish with a clear recommendation, prioritising the highest risk, and link to governance such as policy, training and monitoring.

Quickest way: Risk, control, limit in three lines

When to use it: Use when time is short or the question carries few marks and asks for controls or recommendations.

  1. Write the threat from the scenario in a few words.
  2. Name the matching control and say how it works in one sentence.
  3. Add one limit or condition, such as staff training or key protection, then move on.

Common mistakes in Access Controls, Authentication and Encryption

  • Calling a password plus a security question multi-factor authentication.

    Students count the number of steps rather than the type of proof.

    Fix: Check that the proofs come from different categories: know, have, are.

  • Listing controls without linking them to the scenario.

    Students recall definitions and stop.

    Fix: Use a scenario fact in each point, such as remote sales staff using laptops, then name the control.

  • Saying encryption stops hackers getting into the system.

    Confusing access prevention with data protection.

    Fix: Say encryption makes stolen or intercepted data unreadable without the key. Access controls prevent entry.

  • Ignoring the human side and insiders.

    Students focus on external hackers and firewalls.

    Fix: Include user rights, least privilege, leaver procedures and staff training, since many breaches involve staff.

  • Giving only benefits and no limitations.

    Students assume controls always work.

    Fix: Add costs, inconvenience, weak key management and the need for monitoring, then give a balanced recommendation.

  • Confusing authentication with authorisation.

    Both sound like permission.

    Fix: Authentication asks who you are. Authorisation asks what you may do.

Worked examples

Example 1

Zenith Retail has sales staff who use laptops and phones to access customer records and pricing from client sites. A laptop was recently stolen. The board asks you to recommend controls to reduce the risk of unauthorised access to customer data. (10 marks)

Show the solution
  1. Risk: the stolen laptop could give a thief access both to data stored on it and to the company network.
  2. Authentication: require strong passwords and multi-factor authentication, for example a password plus a code on the employee's phone. A thief with the laptop would still lack the second factor.
  3. Encryption: encrypt laptop storage so that data is unreadable without the key. This protects customer records even if the device is lost.
  4. User rights: apply least privilege so sales staff see only the customers and prices they need, limiting damage if an account is compromised.
  5. Network protection: use a firewall and a secure connection for remote access so that only authorised devices reach internal systems.
  6. Device management: allow remote locking or wiping of lost devices and require staff to report losses immediately.
  7. Limits: MFA and encryption add some inconvenience and cost, so staff training and a clear policy are needed. Keys and recovery codes must themselves be protected.
  8. Recommendation: prioritise encryption and MFA first, since they address the incident directly, then tighten user rights and device management.

Answer: Recommend multi-factor authentication, full-disk encryption, least-privilege user rights, a firewall with secure remote access, and remote wipe, supported by policy and training. Encryption and MFA are the priority because they address the stolen laptop directly.

Example 2

Explain the difference between authentication and authorisation, and explain how encryption differs from a firewall. (8 marks)

Show the solution
  1. Authentication verifies identity. Example: a user enters a password and a one-time code.
  2. Authorisation follows. It sets what the verified user may do, based on user rights. Example: an accounts clerk can view but not approve payments.
  3. Together they make up logical access control. Logging then gives accountability.
  4. A firewall filters traffic between networks against set rules and blocks unauthorised connections. It is a preventive control at the network boundary.
  5. Encryption protects the data itself by making it unreadable without a key. It works even if the data is intercepted or the device is stolen.
  6. Contrast: the firewall tries to keep intruders out, while encryption limits the harm if they get data anyway. Neither replaces the other, so a business uses both as layers.

Answer: Authentication proves who the user is. Authorisation sets what they can do. A firewall controls which traffic can cross a network boundary, while encryption makes data unreadable to anyone without the key. They are complementary layers of defence.

Exam tips

  • Always tie each control to a scenario fact. Generic lists score poorly on the professional skills marks for analysis.
  • Use the know, have, are test whenever MFA appears. It is the quickest way to avoid errors.
  • Show balance: give the benefit, then a limit such as cost, user resistance or key management.
  • In recommendation tasks, prioritise. Say which control addresses the biggest risk first and why.
  • Write short, structured paragraphs or bullets, using headings such as Authentication and Encryption, so the marker can find points quickly.

Practice questions from IT systems security and control

Access Controls, Authentication and Encryption: frequently asked questions

What is multi-factor authentication?

It is a login method requiring two or more different types of proof: something you know, something you have or something you are. A password plus a phone code is an example. It reduces the risk from stolen or guessed passwords.

How does encryption protect data?

Encryption uses an algorithm and a key to turn readable data into ciphertext. Without the correct key, intercepted or stolen data cannot be read. It protects data in transit and at rest, but only if the keys are well managed.

What does a firewall do?

A firewall filters network traffic using rules and blocks connections that are not permitted. It sits between a trusted network and an untrusted one, such as the internet. It does not protect against all threats, for example misuse by authorised staff.

What is the principle of least privilege?

Each user gets only the access rights needed to do their job. This limits the damage from errors, fraud or a compromised account. Rights should be reviewed when roles change or staff leave.