ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium
A company wants to implement a system where access decisions are based on predefined rules or policies, rather than the discretion of the resource owner. For example, all employees in the 'Finance' department automatically get access to the 'Accounting Software' and 'Budget Reports'. Which access control model best fits this description?
- AAttribute-Based Access Control (ABAC)
- BRole-Based Access Control (RBAC)
- CDiscretionary Access Control (DAC)
- DMandatory Access Control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: D. Mandatory Access Control (MAC)
Mandatory Access Control (MAC) is an access control model where access decisions are made based on security labels (e.g., clearance levels) assigned to subjects and objects, enforced by the operating system or security kernel. This often involves predefined, system-wide rules rather than user discretion, aligning with the scenario's 'predefined rules or policies' and automatic assignment based on department (a type of classification).
Why the other options are wrong
- A. ABAC grants access based on attributes of the user, resource, and environment, which is more dynamic and granular than the fixed policy described.
- B. RBAC assigns permissions based on user roles, which is a common implementation but MAC is more about system-wide, non-discretionary enforcement.
- C. DAC allows the owner of a resource to grant or deny access to other users.
Mandatory Access Control (MAC)
An access control model where access decisions are enforced by a central authority based on predefined security labels or classifications, not by the owner of the resource.
- Highly structured and rigid.
- Commonly used in environments with high security requirements (e.g., military, government).
- Prevents users from changing access permissions.
Memory trick: Models control access, mandating rules.