ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A healthcare organization is implementing a new electronic health record (EHR) system. They need to ensure that patient data is protected according to strict regulatory requirements, meaning that access decisions are based on the sensitivity of the data and the clearance level of the user, rather than user discretion. Which access control model best fits this requirement?

  1. ARole-Based Access Control (RBAC)
  2. BDiscretionary Access Control (DAC)
  3. CMandatory Access Control (MAC)
  4. DAttribute-Based Access Control (ABAC)
Show answer & explanation

Correct answer: C. Mandatory Access Control (MAC)

Mandatory Access Control (MAC) enforces a system-wide policy where access decisions are made by the system based on security labels (e.g., classification levels for data, clearance levels for users), not by the data owner. This aligns with strict regulatory requirements for highly sensitive data.

Why the other options are wrong

  • A. RBAC grants access based on job roles, but MAC specifically addresses sensitivity and clearance levels enforced by the system.
  • B. DAC allows data owners to define access, which is contrary to the 'strict regulatory requirements' and 'not user discretion' in the scenario.
  • D. ABAC uses a dynamic set of attributes, which can be part of MAC but MAC is the overarching model for this strict, label-based control.

Mandatory Access Control (MAC)

An access control model where access decisions are enforced by a central authority based on security labels, not by the data owner.

  • System-enforced policy
  • Uses security labels (e.g., classification, clearance)
  • Common in high-security environments (government, military)

Memory trick: DAC: 'I decide.' MAC: 'The system decides.' RBAC: 'My job decides.' ABAC: 'Attributes decide.'

More Access Controls Concepts questions