ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A government agency is designing a new access control system for highly sensitive, classified documents. The system must enforce strict rules where access decisions are based on a subject's clearance level and a document's classification level, with no discretion given to individual users or data owners. Which access control model is most appropriate for this scenario?

  1. AAttribute-Based Access Control (ABAC)
  2. BMandatory Access Control (MAC)
  3. CDiscretionary Access Control (DAC)
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: B. Mandatory Access Control (MAC)

Mandatory Access Control (MAC) is ideal for highly sensitive environments like government agencies dealing with classified information. It enforces a centralized, system-wide policy based on security labels (clearance levels for subjects and classification levels for objects), overriding any individual user's discretion.

Why the other options are wrong

  • A. ABAC uses dynamic attributes but isn't typically the primary model for strict, label-based classified environments.
  • C. DAC allows data owners to decide access, which contradicts the 'no discretion' requirement.
  • D. RBAC assigns permissions based on roles, but often still allows some flexibility or doesn't inherently enforce strict 'no discretion' based on sensitivity labels.

Mandatory Access Control (MAC)

An access control model where the operating system or security kernel enforces access decisions based on security labels (e.g., clearance levels, classification levels), and users cannot override these decisions.

  • Highly secure and rigid.
  • Commonly used in military and government environments.
  • Based on sensitivity labels and subject clearances.

Memory trick: MAC is MANDATORY, like a general's orders for classified files.

More Access Controls Concepts questions