SSCP Systems Security Certified PractitionerAccess ControlsMedium
A company is implementing a new system where access decisions are based on the sensitivity of the data, the clearance level of the user, and a formal classification scheme. This system prevents users from writing information to a lower security level than their current clearance and from reading information from a higher security level. Which access control model is being described?
- ADiscretionary Access Control (DAC)
- BAttribute-Based Access Control (ABAC)
- CRole-Based Access Control (RBAC)
- DMandatory Access Control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: D. Mandatory Access Control (MAC)
Mandatory Access Control (MAC) enforces access decisions based on security labels (sensitivity of data) and clearance levels (user clearance), often following strict rules like 'no write down' and 'no read up', which are characteristic of multi-level security systems.
Why the other options are wrong
- A. DAC allows the owner of a resource to define access permissions, which is not the case here where a central authority dictates access.
- B. ABAC uses a combination of attributes about the user, resource, and environment, which is more dynamic than the strict, label-based MAC described.
- C. RBAC grants permissions based on a user's assigned role, not explicit data sensitivity or clearance levels.
Mandatory Access Control (MAC)
An access control model where a central authority enforces access decisions based on security labels assigned to subjects (users) and objects (resources).
- Strictly enforced, often used in high-security environments.
- Users cannot alter access permissions.
- Commonly implements 'no write down' and 'no read up' rules (e.g., Bell-LaPadula).
Memory trick: Models Manage Access: Decide who sees what.