ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium
A company is implementing a new physical access control system for its data center. The security team wants to ensure that access is granted based on attributes like job role, time of day, and specific project assignment. Which access control model would BEST support this granular, context-aware decision-making?
- AMandatory Access Control (MAC)
- BRole-Based Access Control (RBAC)
- CAttribute-Based Access Control (ABAC)
- DDiscretionary Access Control (DAC)
Show answer & explanationAnswer & explanation
Correct answer: C. Attribute-Based Access Control (ABAC)
ABAC evaluates access requests based on a set of attributes associated with the user, resource, and environment, allowing for highly granular and context-aware access decisions, which perfectly matches the scenario's requirements.
Why the other options are wrong
- A. MAC enforces access based on security labels assigned to subjects and objects, which is typically rigid and not as flexible for dynamic, attribute-based decisions as required.
- B. RBAC grants permissions based on a user's role, which is less granular than ABAC and doesn't inherently account for dynamic attributes like time of day or specific project assignment directly.
- D. DAC allows the owner of a resource to determine who can access it, which is not suitable for centralized, policy-driven granular access based on multiple attributes.
Attribute-Based Access Control (ABAC)
An access control model that grants or denies access based on a set of attributes associated with the user, resource, and environment.
- Highly granular and flexible.
- Uses policies rather than fixed roles or permissions.
- Supports dynamic and context-aware access decisions.
Memory trick: MACs DACs RBACs ABACs: Models All Control Access