StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 5: Identity & access management

Controlling physical and logical access to information, systems, devices, facilities and applications

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Access control is the heart of Domain 5 and, in many ways, of security itself. Its purpose is to ensure that only authorized subjects can reach objects, and only in the ways they are permitted. A subject is an active entity such as a user, process or device that requests access; an object is the passive resource being accessed, such as a file, database, server, room or application. Every access decision answers the same question: may this subject perform this action on this object right now?

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan