ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium

A security auditor is reviewing an organization's access control matrix. The matrix shows that a specific user, 'Alice', has 'read' access to 'Project X' files and 'write' access to 'Project Y' files. The auditor notes that 'Project Y' files are highly sensitive and should only be accessible by project leads. Which access control model is MOST likely being used?

  1. ARole-Based Access Control (RBAC)
  2. BDiscretionary Access Control (DAC)
  3. CAttribute-Based Access Control (ABAC)
  4. DMandatory Access Control (MAC)
Show answer & explanation

Correct answer: B. Discretionary Access Control (DAC)

The scenario describes a user ('Alice') having different explicit permissions ('read', 'write') to different resources ('Project X', 'Project Y') which suggests that the owner or creator of the resource can define access. The issue arises because Alice, presumably not a project lead, has write access to sensitive files, indicating that individual users or owners have discretion over access, characteristic of DAC.

Why the other options are wrong

  • A. RBAC assigns permissions based on job roles. If RBAC were strictly enforced, Alice's role would likely not grant write access to sensitive 'Project Y' files unless she was a project lead.
  • C. ABAC grants access based on a combination of user, resource, and environmental attributes, offering fine-grained control, but the scenario points more directly to individual discretion over permissions, a hallmark of DAC.
  • D. MAC enforces access based on security labels (e.g., classification levels) and would prevent Alice from having write access to 'Project Y' if her clearance didn't match the sensitivity, regardless of an owner's discretion.

Discretionary Access Control (DAC)

DAC allows the owner or creator of a resource to define and control access permissions for that resource.

  • Subject (owner) determines access.
  • Flexible but can lead to inconsistent security policies.
  • Common in many operating systems (e.g., NTFS permissions).

Memory trick: DAC: Discretionary, Owner's Call.

More Identity and Access Management (IAM) questions