SSCP Systems Security Certified PractitionerAccess ControlsHard
An organization is implementing a new system where access to data is dynamically granted or denied based on automated rules that evaluate the user's current network segment, the time of day, and whether their device is compliant with security policies. Users do not directly control permissions, and there are no explicit security labels on the data itself. Which access control model best fits this description?
- ARule-Based Access Control
- BMandatory Access Control (MAC)
- CDiscretionary Access Control (DAC)
- DRole-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: A. Rule-Based Access Control
Rule-Based Access Control (RBAC, not to be confused with Role-Based Access Control) grants or denies access based on a set of predefined rules or conditions, often evaluating environmental factors like network segment, time, and device compliance. Unlike ABAC, it doesn't necessarily rely on attributes of the user or object but on a set of 'if-then' rules.
Why the other options are wrong
- B. MAC relies on strict security labels and clearances, which are explicitly stated as not being present.
- C. DAC allows resource owners to set permissions, which is not the case here as access is based on automated rules.
- D. Role-Based Access Control (RBAC) relies on user roles, not dynamic evaluation of network segment, time, and device compliance.
Rule-Based Access Control
An access control model where access to resources is granted or denied based on a set of predefined rules or policies that evaluate conditions.
- Rules are typically defined by administrators and enforced system-wide.
- Can incorporate environmental factors (e.g., time, location).
- Distinct from Role-Based Access Control, though often confused due to the acronym RBAC sometimes being used for both.
Memory trick: Rules Rule Access: Conditions lead to decisions.