ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A system administrator implements a new access control model where users are assigned to groups, and permissions are then granted to those groups. For example, all users in the 'Developers' group automatically inherit read, write, and execute permissions on specific code repositories. Which access control model is being utilized?

  1. ARole-Based Access Control (RBAC)
  2. BAttribute-Based Access Control (ABAC)
  3. CMandatory Access Control (MAC)
  4. DDiscretionary Access Control (DAC)
Show answer & explanation

Correct answer: A. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) assigns permissions based on a user's role within an organization. In this scenario, 'Developers' is a role (or group representing a role), and users assigned to it inherit specific permissions. This is a classic example of RBAC.

Why the other options are wrong

  • B. ABAC is more granular, using multiple attributes beyond just a role.
  • C. MAC uses security labels and a central authority, not groups inheriting permissions.
  • D. DAC allows resource owners to define access, which is not described.

Role-Based Access Control (RBAC)

An access control model where permissions are associated with roles, and users are assigned to appropriate roles, thereby inheriting the associated permissions.

  • Simplifies access management in large organizations.
  • Promotes the principle of least privilege.
  • Roles are typically defined by job function or responsibility.

Memory trick: Models define access, roles make it easy.

More Access Controls Concepts questions