ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium
A system administrator is configuring access to a new project folder. They assign permissions to the 'Project_A_Team' group, granting them read and write access, and to the 'Project_A_Managers' group, granting them full control. Individual users are then added to these respective groups to inherit their access rights. Which access control model is being implemented?
- ARole-Based Access Control (RBAC)
- BMandatory Access Control (MAC)
- CAttribute-Based Access Control (ABAC)
- DDiscretionary Access Control (DAC)
Show answer & explanationAnswer & explanation
Correct answer: A. Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) assigns permissions to roles (or groups, which often function as roles) rather than directly to individual users. Users then acquire permissions by being assigned to one or more roles.
Why the other options are wrong
- B. MAC uses security labels centrally enforced, not group assignments made by an administrator.
- C. ABAC uses granular attributes, not just roles/groups, for access decisions.
- D. DAC allows object owners to set permissions, but this scenario describes permissions assigned to groups, which is characteristic of RBAC.
Role-Based Access Control (RBAC)
An access control model where permissions are associated with roles, and users are assigned to appropriate roles based on their job function or responsibilities. This simplifies management and enforces the principle of least privilege.
- Widely used in business environments for its simplicity and scalability.
- Permissions are assigned to roles, not directly to users.
- Users inherit permissions by virtue of their role membership.
Memory trick: Roles make access simple, like a play with parts.