A security architect is designing a new cloud-native application that will handle sensitive customer data. To ensure the confidentiality and integrity of this data, the architect wants to enforce strict controls that grant access based on a combination of user attributes (e.g., department, role, security clearance), resource attributes (e.g., data sensitivity, classification), and environmental conditions (e.g., time of day, device posture). Which access control model best supports this dynamic and fine-grained approach?
- AMandatory Access Control (MAC)
- BAttribute-Based Access Control (ABAC)
- CRole-Based Access Control (RBAC)
- DDiscretionary Access Control (DAC)
Show answer & explanationAnswer & explanation
Correct answer: B. Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) is specifically designed to grant or deny access based on a dynamic set of attributes associated with the user, resource, and environment. This allows for highly flexible, fine-grained, and context-aware access decisions, which is precisely what's needed for sensitive customer data with complex access requirements.
Why the other options are wrong
- A. MAC enforces access based on sensitivity labels and clearances, typically used in highly structured environments (e.g., military) and less flexible for dynamic attribute combinations.
- C. RBAC grants access based on a user's assigned role, which is less granular and flexible than ABAC for dynamic, context-aware decisions.
- D. DAC allows resource owners to control access, which can lead to inconsistent security policies and is not suitable for centralized, fine-grained control based on multiple attributes.
Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) is an access control model that grants or denies access to resources based on a set of attributes associated with the user (subject), the resource (object), the action being performed, and environmental conditions. It allows for highly dynamic, flexible, and fine-grained access decisions.
- Uses attributes of user, resource, action, and environment for access decisions.
- Provides highly flexible and fine-grained access control.
- Supports dynamic, context-aware access policies.
- More scalable than RBAC for complex, evolving access requirements.
Memory trick: ABAC Allows Best Attribute-Based Access Control.