CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is designing a system for a highly sensitive research facility that processes classified information. The facility requires an access control model where subjects are assigned a security clearance, and objects (data, resources) are assigned a security classification. Access decisions are strictly based on comparing these labels, ensuring a 'need-to-know' and 'no write-down, no read-up' policy. Which access control model is MOST appropriate for this scenario?

  1. ADiscretionary Access Control (DAC).
  2. BAttribute-Based Access Control (ABAC).
  3. CMandatory Access Control (MAC).
  4. DRole-Based Access Control (RBAC).
Show answer & explanation

Correct answer: C. Mandatory Access Control (MAC).

Mandatory Access Control (MAC) is ideal for highly sensitive environments like classified research facilities. It enforces access decisions based on security labels (clearance levels for subjects and classification labels for objects), strictly adhering to rules like 'no read-up' (cannot read higher classification) and 'no write-down' (cannot write to lower classification), ensuring rigid information flow control.

Why the other options are wrong

  • A. DAC allows resource owners to grant or deny access at their discretion, which is unsuitable for classified environments requiring centralized, strict policy enforcement.
  • B. ABAC uses attributes for access decisions, offering fine-grained control, but MAC specifically addresses the hierarchical classification and 'no read-up, no write-down' rules critical for classified data.
  • D. RBAC grants access based on a user's role, which is too flexible and doesn't enforce strict 'no read-up, no write-down' rules based on security labels.

Mandatory Access Control (MAC)

Mandatory Access Control (MAC) is an access control model where the operating system or security kernel enforces access decisions based on security labels (e.g., classification, clearance) assigned to subjects and objects. Users cannot override these policies.

  • System-wide, centrally enforced policy.
  • Based on security labels (e.g., Top Secret, Secret, Confidential).
  • Enforces 'no read-up' (Simple Security Property) and 'no write-down' (*-property).
  • Common in military, government, and highly sensitive environments.

Memory trick: MAC: Mandatory 'M'ilitary 'A'ccess 'C'ontrol for secrets.

More Security Architecture questions