Access control system architecture — readers, controllers, and the access control server — credential types from proximity cards through smart cards and mobile credentials, and how access levels, zones, and schedules implement least privilege.
An access control system answers one question repeatedly at every door on a site: should this credential be allowed through right now? This module covers the three-layer architecture — reader, controller, and server — that answers that question reliably even through a network outage, the credential technologies (and the OSDP-versus-Wiegand protocol question) that determine how hard a credential is to clone or intercept, and the access levels, zones, and schedules that implement least privilege in a real deployment.
By the end of this module you should be able to explain why a smart card's on-card cryptography does not protect a credential if the reader-to-controller link still uses unencrypted Wiegand — a protocol-level decision Module 14's installation content and Module 16's cyber-physical integration content both return to.