SSCP Systems Security Certified PractitionerAccess ControlsHard
A hospital's patient record system is designed such that medical staff can only access patient records during their active shift and only from designated hospital terminals within the secure network. Access attempts outside of these parameters are automatically denied. Which type of access control mechanism is primarily being used to enforce these restrictions?
- ARule-Based Access Control
- BDiscretionary Access Control (DAC)
- CRole-Based Access Control (RBAC)
- DMandatory Access Control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: A. Rule-Based Access Control
Rule-Based Access Control uses a set of predefined rules to determine access. The scenario specifies conditions like 'during their active shift' (time-based) and 'from designated hospital terminals within the secure network' (location/environment-based), which are classic examples of rules being enforced.
Why the other options are wrong
- B. DAC allows resource owners to set permissions, which is not what's happening here; system-wide rules are being enforced.
- C. RBAC assigns permissions based on a user's role (e.g., 'Doctor'), but doesn't inherently include dynamic conditions like 'during active shift' or 'from designated terminals' without additional rules.
- D. MAC relies on strict security labels and clearances, which is not the primary mechanism for enforcing time and location constraints.
Rule-Based Access Control
An access control mechanism that grants or denies access to resources based on a set of predefined rules or policies. These rules often incorporate conditions like time of day, location, or protocol.
- Highly flexible and dynamic.
- Rules are typically defined by administrators.
- Can be used in conjunction with other models like RBAC or ABAC.
Memory trick: Rules Rule! Time, Place, Action are key.