ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium

A security architect is designing a new access control system for a critical infrastructure facility. The system must ensure that access decisions are based on a comprehensive set of environmental conditions, user attributes, resource attributes, and defined policies, rather than predefined roles or static permissions. Which access control model best fits this requirement?

  1. ARole-Based Access Control (RBAC)
  2. BAttribute-Based Access Control (ABAC)
  3. CDiscretionary Access Control (DAC)
  4. DMandatory Access Control (MAC)
Show answer & explanation

Correct answer: B. Attribute-Based Access Control (ABAC)

Attribute-Based Access Control (ABAC) provides the most granular and dynamic access control by evaluating a combination of attributes (user, resource, environment) and policies in real-time, meeting the requirement for comprehensive, condition-based access decisions.

Why the other options are wrong

  • A. RBAC grants permissions based on a user's role, which is less granular and dynamic than what the scenario describes.
  • C. DAC allows resource owners to define access, which is too decentralized and lacks the dynamic policy enforcement required.
  • D. MAC enforces a strict, hierarchical classification system for access, which is not focused on dynamic environmental conditions and attributes.

Attribute-Based Access Control (ABAC)

An access control model that grants or denies access based on a set of defined attributes (e.g., user, resource, environment) and policies.

  • Highly granular and flexible.
  • Evaluates conditions in real-time.
  • Moves beyond static roles or permissions.

Memory trick: ABAC is the 'A' for All-encompassing Attributes.

More Identity and Access Management (IAM) questions