SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationEasy
A security administrator is configuring access controls for a new project management system. The system requires that only users in the 'Project Managers' group can create new projects, while users in the 'Project Team' group can only view and update existing project tasks. Which access control model is MOST appropriate for implementing these granular permissions?
- AAttribute-Based Access Control (ABAC)
- BDiscretionary Access Control (DAC)
- CMandatory Access Control (MAC)
- DRole-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: D. Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) is ideal for this scenario because it assigns permissions to roles (e.g., 'Project Managers', 'Project Team'), and users are then assigned to those roles, simplifying granular permission management.
Why the other options are wrong
- A. ABAC grants access based on a combination of attributes (user, resource, environment), which is more complex than needed for this scenario and goes beyond simple role-based assignments.
- B. DAC allows the owner of a resource to grant or deny access, which can lead to inconsistent and unmanageable permissions in a large system.
- C. MAC is typically used in highly secure environments (e.g., military) where access is based on security labels, not user roles.
Role-Based Access Control (RBAC)
RBAC is an access control model where permissions are associated with roles, and users are assigned to appropriate roles, simplifying permission management.
- Permissions granted based on job functions/roles
- Simplifies administration in large organizations
- Most common access control model in business applications
Memory trick: MAC is strict, DAC is loose, RBAC is roles, ABAC is attributes.