SSCP Systems Security Certified PractitionerAccess ControlsHard

A security architect is designing an access control system for a highly dynamic environment where access decisions must be made in real-time based on a combination of a user's current location, the time of day, their role, and the sensitivity level of the data they are trying to access. Which access control model would be most suitable for this complex requirement?

  1. AMandatory Access Control (MAC)
  2. BRole-Based Access Control (RBAC)
  3. CAttribute-Based Access Control (ABAC)
  4. DDiscretionary Access Control (DAC)
Show answer & explanation

Correct answer: C. Attribute-Based Access Control (ABAC)

Attribute-Based Access Control (ABAC) is designed for highly dynamic and granular access control. It evaluates a set of attributes (user, object, environment) to make real-time access decisions, perfectly matching the complex requirements described.

Why the other options are wrong

  • A. MAC is label-based and static, not flexible enough for real-time evaluation of multiple environmental and user attributes.
  • B. RBAC is based on roles and permissions assigned to those roles, which can become unwieldy with many dynamic conditions.
  • D. DAC is decentralized and relies on resource owners, not suitable for real-time, dynamic, multi-attribute decisions.

Attribute-Based Access Control (ABAC)

An access control model that grants or denies access to resources based on a combination of attributes associated with the subject (user), object (resource), action, and environment.

  • Offers highly granular and dynamic control.
  • More flexible than RBAC or MAC for complex scenarios.
  • Requires a robust policy decision point (PDP) and policy enforcement point (PEP).

Memory trick: ABAC: Attributes All Around, Decisions profound.

More Access Controls questions