CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A healthcare organization is designing a new patient management system that handles Electronic Health Records (EHR). Due to regulatory compliance (e.g., HIPAA), the system must ensure that patient data is securely partitioned, and access is strictly controlled based on the user's role and the sensitivity classification of the data, regardless of any discretionary access controls. Which access control model is BEST suited for enforcing such strict, rule-based access?

  1. AMandatory Access Control (MAC).
  2. BRole-Based Access Control (RBAC).
  3. CDiscretionary Access Control (DAC).
  4. DAttribute-Based Access Control (ABAC).
Show answer & explanation

Correct answer: A. Mandatory Access Control (MAC).

Mandatory Access Control (MAC) is best suited for environments with strict regulatory compliance and highly sensitive data, like EHRs. MAC enforces access decisions based on security labels (e.g., classifications) assigned to subjects and objects, overriding any discretionary settings, thus ensuring that access is strictly controlled by system-wide rules and not user preferences.

Why the other options are wrong

  • B. RBAC assigns permissions based on user roles, which is good for managing access, but MAC provides a stronger, system-wide, non-discretionary enforcement based on sensitivity labels.
  • C. DAC allows resource owners to grant or deny access at their discretion, which is too flexible for environments requiring strict, system-wide policy enforcement.
  • D. ABAC grants access based on a combination of attributes (user, resource, environment), offering fine-grained control, but MAC specifically emphasizes the non-discretionary, system-wide enforcement via labels, which is stronger for the given scenario.

Mandatory Access Control (MAC)

Mandatory Access Control (MAC) is an access control model where the operating system or security kernel enforces access decisions based on security labels assigned to subjects (users, processes) and objects (files, data).

  • Access decisions are not at the discretion of the owner.
  • Based on sensitivity labels (e.g., top secret, confidential).
  • Used in highly secure environments (military, government, healthcare).
  • Strongest form of access control for strict enforcement.

Memory trick: MAC is like a 'military clearance' system for your data—no exceptions, no discretion.

More Security Architecture questions