ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsHard

A global manufacturing company uses a complex network of industrial control systems (ICS) and IT systems. Due to the critical nature of their operations, they need an access control model that can dynamically grant or deny access based on a combination of factors such as the user's role, the time of day, the location from which they are accessing, and the sensitivity of the data being requested. Which access control model is best suited for this highly granular and context-aware requirement?

  1. AMandatory Access Control (MAC)
  2. BDiscretionary Access Control (DAC)
  3. CAttribute-Based Access Control (ABAC)
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: C. Attribute-Based Access Control (ABAC)

Attribute-Based Access Control (ABAC) is designed for highly granular and dynamic access decisions. It evaluates a set of attributes (user attributes, resource attributes, environmental attributes like time/location) in real-time against predefined policies to determine access. This flexibility makes it ideal for complex, context-aware requirements like those described.

Why the other options are wrong

  • A. MAC is static and label-based, not dynamic or context-aware enough for this scenario.
  • B. DAC relies on object owners, which is not suitable for a highly controlled, dynamic environment.
  • D. RBAC is based on roles and is less dynamic or granular for combining multiple factors like time and location.

Attribute-Based Access Control (ABAC)

An access control model that grants or denies access based on a dynamic set of attributes associated with the user, resource, and environment.

  • Highly granular and flexible
  • Uses policies rather than fixed roles/labels
  • Context-aware (e.g., time, location, device)

Memory trick: ABAC is like a customizable puzzle, where every piece (attribute) matters.

More Access Controls Concepts questions