Cost and Management Audit · Information Systems Security Audit
Logical and Physical Access Controls in Information Systems Security Audit
Updated 11 October 2026 · Fact-checked
Access controls stop unauthorised people from using IT assets. Logical controls protect data and software through authentication, authorisation, passwords, firewalls and encryption. Physical controls protect buildings, servers and devices through locks, guards and surveillance. To answer a question, name the risk, match the control, and say what it prevents.
Understand Logical and Physical Access Controls
Every information system holds assets worth protecting: data, programs, networks and hardware. Access control is the set of measures that decide who can reach these assets and what they can do with them. If access is weak, fraud, data theft and tampering with cost records become easy.
There are two families. Logical access controls work through software and settings. They guard data, applications, operating systems and networks. Physical access controls work in the real world. They guard the premises, server rooms, cabling and devices.
Logical control starts with two steps that students often mix up. Authentication asks "Who are you?" and checks identity, using something you know (password, PIN), something you have (token, smart card, OTP device) or something you are (fingerprint, iris, face). Using two or more of these is multi-factor authentication. Authorisation asks "What are you allowed to do?" It applies after identity is proved, through user roles, access rights and permissions such as read, write, approve or delete.
Other logical tools support these. A firewall filters network traffic between a trusted network and an untrusted one, such as the internet, using defined rules. Encryption converts readable data into unreadable form using a key, so intercepted or stolen data cannot be understood. A digital signature uses encryption to prove who sent a document and that it was not altered. Good password policy, account lockout, logging of access and periodic review of user rights complete the picture.
Physical controls include locks, access cards, biometric door readers, security guards, visitor registers, CCTV, alarms, fire and water protection, restricted entry to the data centre, and secure disposal of old devices. The auditor tests whether these controls exist, are applied in practice, and are reviewed.
Key rules to remember
- Authentication vs authorisation
- Authentication = proving identity; Authorisation = permitted actions after identity is proved
- Authentication always comes first. Say this order in answers.
- Authentication factors
- Something you know + something you have + something you are
- Two or more different factors make multi-factor authentication. Two passwords are not multi-factor.
- Logical vs physical
- Logical = software-based, protects data and systems; Physical = hardware and premises-based, protects facilities and devices
- Use this as the first line of any difference question.
- Digital signature assurance
- Digital signature = authenticity + integrity + non-repudiation
- It does not by itself keep content secret. That is encryption's job.
- Principle of least privilege
- Give each user only the access needed for their job
- Link it to segregation of duties in audit answers.
How to solve Logical and Physical Access Controls questions
Use this method for any question on access controls, whether it is a short note, a difference or a case on a weak system.
- 1Read the question and identify the asset at risk: data, application, network, server room or devices.
- 2Classify the weakness or requirement as logical or physical.
- 3Name the matching control precisely: authentication, authorisation, password rule, firewall, encryption, biometric lock, CCTV and so on.
- 4Explain how it works in one or two lines, in plain words.
- 5State the risk it reduces, such as unauthorised access, data theft, alteration or loss.
- 6Add the audit angle: what the auditor would inspect, such as access logs, user rights lists, visitor registers or firewall rules.
- 7Close with a short recommendation if the question describes a weakness.
Quickest way: Risk, control, evidence in three lines
When to use it: Use when time is short, especially for 2-mark MCQs and short notes.
- Ask: is this about who the user is (authentication), what they may do (authorisation), or where the asset sits (physical)?
- Match keywords: password, OTP, biometric means authentication; role, rights, permissions means authorisation; guard, lock, CCTV means physical; key, ciphertext means encryption; traffic filtering means firewall.
- Write the control, the risk it stops and one audit check.
Common mistakes in Logical and Physical Access Controls
Using authentication and authorisation as if they mean the same thing.
Both appear during login and sound alike.
Fix: Remember: authentication proves identity; authorisation sets permitted actions afterwards. Always write them in that order.
Saying a firewall protects against all threats, including viruses and insider misuse.
Students treat it as a complete security solution.
Fix: State that a firewall filters network traffic by rules. It needs antivirus, access rights and monitoring beside it.
Treating a digital signature as the same as encryption.
Both use cryptographic keys.
Fix: Encryption gives confidentiality. A digital signature gives authenticity, integrity and non-repudiation.
Calling a password plus a security question multi-factor authentication.
Two steps look like two factors.
Fix: Both are something you know. Multi-factor needs different categories, such as password plus OTP device.
Ignoring physical controls in IS audit answers.
IS audit feels software-only.
Fix: Always check premises, server room entry, visitor logs and device disposal. Strong software controls fail if anyone can walk in and take a server.
Listing controls without linking them to risks.
Students memorise lists.
Fix: Write each control with the risk it reduces and what an auditor would verify.
Worked examples
Example 1
Distinguish between logical access controls and physical access controls, giving two examples of each.
Show the solution
- Define logical controls: software-based measures that restrict access to data, applications and networks.
- Define physical controls: measures that restrict physical access to premises, equipment and media.
- Compare on nature: logical are technical and digital; physical are tangible.
- Compare on purpose: logical stop unauthorised use of data and systems; physical stop theft, damage and unauthorised entry.
- Give examples: logical: passwords, firewalls. Physical: biometric door locks, CCTV.
- Add the audit angle: the auditor tests user rights and logs for logical controls, and entry registers and room security for physical controls.
Answer: Logical access controls are software-based safeguards (for example passwords and firewalls) protecting data and systems. Physical access controls are tangible safeguards (for example biometric door locks and CCTV) protecting premises and equipment. Both are needed, because failure of either exposes the information system.
Example 2
During an audit of a manufacturing company, you find that all accounts staff share one login for the costing software, the server sits in an unlocked room near the stores, and backup tapes are left on a desk. Identify the weaknesses and recommend controls.
Show the solution
- Shared login: individual identity cannot be proved, so authentication fails and actions cannot be traced. Recommend unique user IDs, strong passwords and, for sensitive functions, an OTP or token as a second factor.
- Same access for all staff: no authorisation by role. Recommend role-based rights on least privilege, so entry, approval and change rights are separated.
- Unlocked server room: a physical control gap. Recommend a locked room, access cards or biometric entry, a visitor register and CCTV.
- Backup tapes on a desk: risk of theft or loss. Recommend locked storage, off-site custody and encryption of backups.
- Add monitoring: enable access logs and review them periodically, and review user rights at fixed intervals.
Answer: The weaknesses are shared credentials (authentication), no role-based rights (authorisation), an unsecured server room and unprotected backups (physical). Unique IDs with stronger authentication, role-based permissions, restricted and monitored room entry, and locked, encrypted backups, with regular log and rights review, would fix them.
Exam tips
- MCQs often test the pair authentication and authorisation. Check whether the stem is about identity or permissions.
- In case scenarios, scan for both a logical and a physical lapse. Cases usually plant one of each.
- For short notes on firewall, encryption or digital signature, write what it is, how it works, what it protects and one limitation.
- Use the risk, control, audit check pattern so answers read as application rather than recall.
- Do not guess a technical detail you are unsure of. A clear plain-words explanation earns more than a wrong technical claim.
Practice questions from Information Systems Security Audit
- An auditor finds that a cost accounting application's database administrator can also approve journal entries and delete audit log records. …
- During an IS security audit at a manufacturing company in Pune, the auditor finds that several former employees' user IDs remain active in t…
- Which of the following best describes the purpose of a 'segregation of duties' control in a computerised cost accounting environment?
- During an IS audit of a manufacturing company's ERP, the auditor wants to confirm that a programmer cannot both modify production code and m…
- An auditor reviewing a company's ERP finds that the same employee can create a vendor master record, approve purchase orders to that vendor …
Logical and Physical Access Controls: frequently asked questions
What is the difference between logical and physical access controls?
Logical access controls are software-based and protect data, applications and networks, for example passwords and firewalls. Physical access controls protect premises and equipment, for example locks, guards and CCTV. A secure system needs both.
What is the difference between authentication and authorisation?
Authentication verifies who the user is, using a password, token or biometric. Authorisation decides what that verified user may do, such as view, edit or approve. Authentication comes first.
Are encryption and digital signature the same?
No. Encryption keeps data unreadable to those without the key, giving confidentiality. A digital signature proves who sent a document and that it was not changed, giving authenticity, integrity and non-repudiation.
What physical controls does a data centre need?
Typical controls are restricted entry through access cards or biometrics, a visitor register, guards, CCTV, alarms, and fire and water protection. Secure handling of backup media and disposal of old devices also matter.