ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsEasy

An organization is implementing an access control model where a central authority strictly defines and enforces access rules based on security labels assigned to subjects and objects. Users cannot modify these access permissions, even for files they own. Which access control model is being described?

  1. AAttribute-Based Access Control (ABAC)
  2. BRole-Based Access Control (RBAC)
  3. CMandatory Access Control (MAC)
  4. DDiscretionary Access Control (DAC)
Show answer & explanation

Correct answer: C. Mandatory Access Control (MAC)

Mandatory Access Control (MAC) is characterized by a central authority enforcing strict access rules based on security labels, preventing users from altering permissions, even for their own resources.

Why the other options are wrong

  • A. ABAC grants access based on various attributes, but the core concept of strict, unchangeable, centrally enforced labels points to MAC.
  • B. RBAC assigns permissions based on job function, not strict security labels enforced by a central authority.
  • D. DAC allows object owners to control access, which contradicts the scenario.

Mandatory Access Control (MAC)

An access control model where access decisions are centrally controlled and strictly enforced by the system based on security labels assigned to subjects and objects. Users cannot override these policies.

  • Often used in high-security environments (e.g., military, government).
  • Based on security classifications (e.g., Top Secret, Secret, Confidential).
  • Users cannot grant or deny access, even to their own files.

Memory trick: DAC is 'discretionary' for you; MAC is 'mandatory' for all.

More Access Controls Concepts questions