ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsHard

An organization is designing a new access control system for its highly sensitive data. The requirement states that access to specific data objects must be explicitly granted by the owner of that data, and the owner retains full control over who can access their data and what actions they can perform. Which access control model is being described?

  1. ADiscretionary Access Control (DAC)
  2. BRole-Based Access Control (RBAC)
  3. CMandatory Access Control (MAC)
  4. DAttribute-Based Access Control (ABAC)
Show answer & explanation

Correct answer: A. Discretionary Access Control (DAC)

Discretionary Access Control (DAC) is characterized by the data owner's ability to grant or revoke access to their resources. The scenario explicitly states that 'access...must be explicitly granted by the owner' and 'the owner retains full control', which are the defining characteristics of DAC.

Why the other options are wrong

  • B. RBAC assigns permissions based on roles, not direct owner control over specific objects.
  • C. MAC enforces access based on system-wide security labels, not owner discretion.
  • D. ABAC grants access based on attributes of the user, resource, and environment, which is more flexible and dynamic than owner-centric control.

Discretionary Access Control (DAC)

An access control model where the owner of a resource (or an administrator with equivalent privileges) has full control over who can access that resource and what permissions they have.

  • Common in many operating systems (e.g., Windows, Unix).
  • Access decisions are 'discretionary' to the owner.
  • Can be less secure if owners are not careful with permissions.

Memory trick: Models control access, owners decide discretion.

More Access Controls Concepts questions