
What are access control basics and why do they matter?
Definition and scope of access control basics
Short definition of access control
Access control is the set of policies, devices, and procedures that permit or deny a subject, such as a person or process, access to a passive object like a door, file, or device. In other words, access control decides who or what can reach a protected resource and enforces that decision at the point of entry or use. This definition aligns with guidance from the Canadian Centre for Cyber Security, which describes access control as controls that govern relationships between active entities and passive entities within a system.
What access control covers
Access control combines two related activities: authentication, which verifies identity, and authorization, which decides what an authenticated identity can do. It ranges from mechanical locks and electrified door hardware to card readers, biometric scanners, controllers, and software that logs and manages access rights. Technical guidance notes that access control spans both physical entry points and digital resources, and that systems should document who or what is allowed access to each resource.
Why access control matters for physical spaces and digital systems
Good access control reduces theft, vandalism, accidental exposure of sensitive data, and the risk of insider misuse by limiting access to the minimum required. For organisations and homeowners, it also provides an audit trail that helps investigate incidents. The Canadian Centre for Cyber Security emphasises access control as a core control that supports broader cyber security and privacy risk management.
Core components of an access control system
Readers and credentials
Readers are the devices that accept credentials, typically mounted beside doors or entry points. Credentials are the tokens used for authentication, such as proximity cards, fobs, PINs entered on a keypad, biometric templates, or mobile credentials presented via Bluetooth or NFC. A reader reads the credential and forwards that information to a controller for a decision.
Controllers and panels
Controllers or panels make the authorization decision. They check the presented credential against an access control database and tell the lock to release or remain locked. Controllers can be local to a single door or networked to a central management system for multiple doors and sites.
Electrified door hardware and locks
Door hardware is the physical interface that secures and controls a door. It includes mechanical locks, electric strikes, magnetic locks, and electrified mortise locks. Proper specification begins with ensuring the door is hung and secured, then selecting hardware that supports the desired control and protection level. For guidance on mechanical versus electrified hardware and specification steps, see Allegion's Door Hardware 101.
Management software and logs
Management software provides the administrative interface to create users, assign permissions, schedule access times, and review access logs. Logs record who attempted access, when, and whether entry was granted. These records are essential for audits and incident response.
Infrastructure needs: power and cabling
Access control requires reliable power and, for most modern systems, network connectivity or dedicated cabling between readers, controllers, and servers. Planning cabling and power feeds is a standard part of installation so the system is resilient and maintainable.
True Vision Surveillance installs and integrates wiring and access hardware across Canada and can advise on cabling or electrified hardware choices during a site survey.
Common authentication methods and operational tradeoffs

Key card and fob systems
Pros: Simple to operate, inexpensive per user, widely supported. Cons: Cards can be lost or shared, and physical tokens must be issued and revoked. Card systems provide a clear audit trail when integrated with management software.
PIN and keypad systems
Pros: No physical token required. Cons: PINs are easily observed or shared, and single-factor PIN access offers weaker assurance than multi-factor options.
Biometric readers
Pros: Strong identity assurance when implemented correctly, convenient for users who do not carry tokens. Cons: Cost is higher, environmental or hygiene factors can affect reliability, and biometric data requires careful privacy handling and protection in storage and transmission.
Mobile credentials and Bluetooth or NFC
Pros: Uses a device most users already carry, supports remote credential management and push notifications. Cons: Dependence on user devices and batteries, interoperability considerations, and the need to secure mobile credential provisioning and lifecycle.
When to use multi-factor authentication
Multi-factor authentication, combining two or more of the methods above, is appropriate where higher assurance is required, for example server rooms, records storage, or administrative consoles. Multi-factor methods make unauthorised access more difficult and are a recommended defence for high-risk areas.
For an overview of how credential types change the operational picture, consult industry guides such as PasWord Protection's overview.
How physical and logical access control differ and when each matters
Examples where only physical control is needed
For simple perimeter security or a supply closet, physical controls such as locks, card readers, or turnstiles may be sufficient. These controls restrict who enters a space without necessarily connecting to digital systems.
Examples requiring logical controls
When access protects data, applications, or networked devices, logical controls such as directory authentication, role based access, and application permissions are necessary. Logical controls ensure that authorised users can only view or modify the specific digital resources they need.
When to integrate physical and logical controls
Integration is important when physical access and digital privileges must be coordinated, for example when physical entry to a server room must be paired with an administrative login, or when an employee’s building access should be revoked automatically when their network account is disabled. Canadian guidance for protecting specified information recommends enforcing physical access authorisations at facility entry and exit points and verifying individual authorisations before granting access to restricted facilities. See the guidance at the Canadian Centre for Cyber Security: Protecting specified information.
Key security principles and insider risk considerations
Why the principle of least privilege matters
The principle of least privilege means granting users only the access they need to perform their role. This reduces the potential damage from compromised or malicious accounts and is emphasised in Canadian cyber security guidance as a core control for reducing insider risk.
How logging and periodic reviews reduce insider risk
Consistent logging of access events and scheduled reviews of permissions reveal anomalies and help detect or deter insider misuse. Periodic audits ensure that former employees or role changes do not leave unnecessary access in place.
Basic hardening steps
Hardening an access control deployment includes timely patching of management software, enforcing strong authentication for administrative consoles, backing up configuration and logs, and defining an account lifecycle process for provisioning and revocation. The Canadian Centre for Cyber Security lists these as baseline controls for organisations to reduce cyber threats: Introduction to the baseline controls.
Canadian context: compliance and practical implications

Facility entry and exit enforcement expectations
For facilities holding sensitive or specified information, Canadian guidance requires enforcing physical access authorisations at entry and exit points. That means verifying individual authorisations before admitting people into restricted areas and using recorded physical access controls such as card readers or guards where appropriate.
Protecting specified information in non-government systems
Organisations storing sensitive information outside of government systems should follow the same access enforcement and verification practices recommended by Canadian authorities. This includes designing access zones, maintaining records, and using control systems that can demonstrate who accessed what and when.
Practical implications for small businesses and homes
Small businesses can achieve meaningful security improvements with modest investments in card readers, managed user accounts, and basic logging. For homes, smart locks and controlled access to outbuildings or storage areas provide convenience and traceability without enterprise complexity. In both cases, plan for credential management and a way to revoke access quickly when keys or devices are lost.
How access control connects to CCTV, cabling and smart locks
Why network cabling matters for reliability
Many access control components rely on structured cabling for power and network connectivity. Proper cabling ensures consistent operation, predictable maintenance, and easier troubleshooting. A qualified installer will include cabling plans as part of a site survey.
How CCTV and access logs work together for investigations
When access logs are correlated with video footage, investigators can confirm identities, timelines, and movements during an incident. Integrating CCTV with access control improves forensic outcomes and helps prevent false claims or misunderstandings.
When smart locks are appropriate
Smart locks are a cost effective option for residential settings and low risk commercial doors. They are simpler to retrofit than full access control systems but may offer fewer management features and weaker audit trails unless paired with a managed platform.
True Vision Surveillance offers CCTV installation, network cabling, smart lock and doorbell setup, and system integration across Canada. If you plan combined CCTV and access control, discuss integrated logging and cabling during the initial site visit.
How to move from research to a quote: questions to ask an installer
Site survey and scope questions
- Will you perform an on site survey to confirm door types, frame conditions, power availability, and cable runs?
- Which doors do you recommend electrifying and why?
- Can you document the required infrastructure changes and provide a drawing or scope of work?
Technical questions
- What credential types do you support and how are they managed?
- How is power supplied and will battery backup or uninterrupted power be required?
- How will the system be networked and what cabling standards do you use?
Operational questions
- Who can administer the system and what training is included?
- How are users provisioned and removed, and can accounts be synchronised with existing directories?
- What logging, reporting, and retention options are available?
Procurement and support questions
- What warranty and service level agreements do you offer?
- Do you provide remote management or on site maintenance plans?
- Which documentation will you hand over, including wiring diagrams and credential inventories?
Installers typically ask for building plans, door schedules, and a list of current keys or access roles, so gather that documentation ahead of the survey. When you are ready to discuss a combined CCTV, cabling, and access control project, contact True Vision Surveillance for a national service consultation or call the phone number on their site.
Frequently asked questions
What is the difference between physical and logical access control?
Physical access control restricts entry to locations and devices, using locks, readers, and barriers. Logical access control manages access to digital resources such as networks, files, and applications. Both protect assets but operate at different layers, and they are often integrated for complete protection.
Do I need an access control system for my home or small business?
If you store valuable inventory, sensitive records, or want audit trails for staff access, an access control system adds measurable security. For many homes, smart locks and monitored doorbells provide sufficient control. The choice depends on risk, budget, and how much administration you want to manage.
Which authentication method is most secure for everyday use?
Multi-factor options that combine something you have with something you know or are provide the best balance of security and usability. For many sites, a card or mobile credential combined with a PIN or biometric for high security areas is appropriate.
How does access control work with CCTV and network cabling?
CCTV provides visual verification to complement access logs. Both systems often share network infrastructure and should be planned together so cabling, switch capacity, and power are adequate for continuous operation and recording.
What should I expect during an access control site survey?
An installer will inspect doors, frames, electrified hardware compatibility, power sources, cable paths, and network access. They will also ask about user roles, hours of operation, and any integration needs with existing CCTV or IT systems.
Key takeaway: come prepared with building plans, a list of who needs access and when, and any existing security hardware details to get an accurate quote.
Ready to discuss your access control needs? Contact True Vision Surveillance for a consultation and site survey.