ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium
A security architect is designing a new access control system for a critical infrastructure facility. The system must ensure that access decisions are based on a comprehensive set of environmental conditions, user attributes, resource attributes, and defined policies, rather than predefined roles or static permissions. Which access control model best fits this requirement?
- ARole-Based Access Control (RBAC)
- BAttribute-Based Access Control (ABAC)
- CDiscretionary Access Control (DAC)
- DMandatory Access Control (MAC)
Show answer & explanationAnswer & explanation
Correct answer: B. Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) provides the most granular and dynamic access control by evaluating a combination of attributes (user, resource, environment) and policies in real-time, meeting the requirement for comprehensive, condition-based access decisions.
Why the other options are wrong
- A. RBAC grants permissions based on a user's role, which is less granular and dynamic than what the scenario describes.
- C. DAC allows resource owners to define access, which is too decentralized and lacks the dynamic policy enforcement required.
- D. MAC enforces a strict, hierarchical classification system for access, which is not focused on dynamic environmental conditions and attributes.
Attribute-Based Access Control (ABAC)
An access control model that grants or denies access based on a set of defined attributes (e.g., user, resource, environment) and policies.
- Highly granular and flexible.
- Evaluates conditions in real-time.
- Moves beyond static roles or permissions.
Memory trick: ABAC is the 'A' for All-encompassing Attributes.