ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A large e-commerce company is implementing a new customer loyalty program. They want to ensure that access to sensitive customer purchase history is restricted. Access should be granted based on the user's department (e.g., Marketing, Customer Service) and their specific role within that department (e.g., Senior Analyst, Team Lead). Which access control model best fits these requirements?

  1. AAttribute-Based Access Control (ABAC)
  2. BMandatory Access Control (MAC)
  3. CDiscretionary Access Control (DAC)
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: D. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) assigns permissions to roles, and then users are assigned to those roles. This aligns perfectly with the scenario where access is based on a user's department and specific role within it, as these would be defined roles.

Why the other options are wrong

  • A. ABAC uses dynamic attributes about the user, resource, and environment for access decisions, which is more granular than typical roles and departments.
  • B. MAC uses sensitivity labels and clearance levels, which is more rigid and typically for highly classified environments, not departmental roles.
  • C. DAC allows data owners to define access, which isn't the structured, organization-wide approach described.

Role-Based Access Control (RBAC)

An access control model where permissions are associated with roles, and users are assigned to appropriate roles, thereby inheriting the permissions of those roles.

  • Simplifies management for large organizations.
  • Access is granted based on job function or responsibility.
  • Users gain access by being assigned to one or more roles.

Memory trick: Roles give you the keys to the kingdom based on your job.

More Access Controls Concepts questions