SSCP Systems Security Certified PractitionerAccess ControlsEasy
A security administrator is configuring access for a new human resources application. The application requires that users can only read their own personnel files but can view an aggregated, anonymized report of all employee salaries. What access control model best supports this specific requirement?
- ARole-Based Access Control (RBAC)
- BDiscretionary Access Control (DAC)
- CContext-Based Access Control
- DMandatory Access Control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: C. Context-Based Access Control
Context-Based Access Control (CBAC) allows access decisions to be made based on environmental factors and the specific context of the request, such as the user's role, the time of access, the data being accessed, and the action being performed. This flexibility is ideal for scenarios where access varies dynamically based on the situation.
Why the other options are wrong
- A. RBAC assigns permissions based on roles, but typically doesn't handle fine-grained, dynamic access based on the specific data content or context of the request.
- B. DAC grants users control over their own resources, but struggles with dynamic, context-dependent rules for different data types.
- D. MAC is based on strict security labels and clearances, which is typically too rigid for this type of scenario.
Context-Based Access Control (CBAC)
An access control model where decisions are made based on the context of the access request, including factors like user identity, time, location, data sensitivity, and the operation being performed.
- Provides highly granular and dynamic access control.
- Considers environmental and situational attributes.
- Often used in environments with complex, changing access requirements.
Memory trick: Contextual Chameleon: Access changes color with the situation.