CompTIA Data+ (DA0-002)Data Governance, Quality and ControlsMedium
A hospital wants to restrict access to electronic patient records based on a combination of dynamic factors, including the requester's department, whether the requester is on the patient's assigned care team, and the time of day the request is made. Which access control model best supports this requirement?
- ADiscretionary Access Control (DAC)
- BRole-Based Access Control (RBAC)
- CAttribute-Based Access Control (ABAC)
- DMandatory Access Control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: C. Attribute-Based Access Control (ABAC)
ABAC evaluates multiple contextual attributes (department, relationship to patient, time of day) at the time of the access request to make dynamic decisions. RBAC only considers a static job role, DAC leaves access decisions to the data owner's discretion, and MAC relies on fixed classification labels set by a central authority.
Why the other options are wrong
- A. DAC allows the resource owner to grant access at their discretion, not policy-driven attribute evaluation.
- B. RBAC grants access purely based on assigned job role, not multiple contextual attributes.
- D. MAC uses fixed, centrally assigned classification labels rather than dynamic contextual attributes.
Attribute-Based Access Control (ABAC)
An access control model that grants permissions based on evaluating multiple attributes of the user, resource, and environment (e.g., department, time, location) against policy rules.
- More granular and dynamic than RBAC
- Can incorporate context such as time of day or location
- Commonly used where access needs change frequently, like healthcare
Memory trick: ABAC = Attributes Assembled Before Access Control decision