ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsHard

A security architect is designing a system where access permissions are granted or denied based on a dynamic set of conditions, including the user's department, the time of day, the sensitivity of the data being accessed, and the location from which the access request originates. Which access control model would be most appropriate for this complex, context-aware requirement?

  1. AMandatory Access Control (MAC)
  2. BAttribute-Based Access Control (ABAC)
  3. CRole-Based Access Control (RBAC)
  4. DDiscretionary Access Control (DAC)
Show answer & explanation

Correct answer: B. Attribute-Based Access Control (ABAC)

Attribute-Based Access Control (ABAC) is the most suitable model for complex, dynamic, and context-aware access decisions as it evaluates various attributes of the subject (user), object (resource), action, and environment (time, location) in real-time.

Why the other options are wrong

  • A. MAC is based on static security labels, not a flexible combination of environmental and user attributes.
  • C. RBAC is based on static roles, not dynamic conditions like time, location, or data sensitivity.
  • D. DAC is based on owner discretion, not dynamic attributes.

Attribute-Based Access Control (ABAC)

An access control model that grants or denies access based on a set of attributes associated with the subject (user), object (resource), action, and environment. It offers fine-grained, dynamic, and context-aware access decisions.

  • Highly flexible and scalable for complex environments.
  • Decisions are dynamic, based on real-time evaluation of attributes.
  • Can incorporate context like time of day, location, device type, and data sensitivity.

Memory trick: ABAC: Access By All Conditions.

More Access Controls Concepts questions