ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringHard

A global enterprise is designing its network infrastructure to support highly confidential data processing across multiple international sites. Due to stringent regulatory requirements, the solution must ensure that data processed in one country cannot be accessed by personnel whose roles are restricted to other countries, even if they have equivalent clearance levels. Which security architecture element is most effective in enforcing this type of strict, context-aware access control based on geographical or organizational separation?

  1. ARole-Based Access Control (RBAC) with global roles and permissions.
  2. BDiscretionary Access Control (DAC) managed by local data owners.
  3. CMandatory Access Control (MAC) with a single global security label hierarchy.
  4. DAttribute-Based Access Control (ABAC) integrating geographical and role attributes.
Show answer & explanation

Correct answer: D. Attribute-Based Access Control (ABAC) integrating geographical and role attributes.

Attribute-Based Access Control (ABAC) is highly effective for complex, context-aware access control scenarios. It allows access decisions to be based on a combination of attributes of the subject (e.g., country of origin), object (e.g., data's country of processing), action (e.g., read, write), and environment (e.g., time of day). This enables the fine-grained, dynamic control needed to enforce restrictions based on geographical and organizational separation, even for users with similar clearance levels.

Why the other options are wrong

  • A. RBAC, while managing roles, might struggle to dynamically enforce access based on the 'country of processing' attribute of the data and the 'country of role' of the user without an extremely complex and potentially unmanageable number of roles.
  • B. DAC relies on data owners, which is decentralized and prone to inconsistencies, making it unsuitable for stringent, enterprise-wide regulatory requirements.
  • C. MAC with a single global hierarchy might be too rigid and not granular enough to differentiate access based on country for users with the 'same' clearance level, without complex and potentially brittle label definitions.

Attribute-Based Access Control (ABAC)

An authorization model that grants or denies access to objects based on the attributes of the subject, object, action, and environment.

  • Highly flexible and granular access control.
  • Decisions are dynamic and context-aware.
  • Scales well for complex policies and many resources/users.

Memory trick: ABAC Adapts to All Attributes and Contexts.

More Security Architecture and Engineering questions