ACCESS CONTROL Flashcards
Known as an identity based access control model
Discretionary access control
A central authority determines which files a user can access
Non discretionary access control
Best describes a rule based access control model
Uses global rules to apply to all users equally
Access control model on a firewall
Rule based
What type of access controls rely on the use of labels
Mandatory
Characteristic of mandatory access control
Prohibitive
Role based access control
Groups users into roles based on organisations hierarchy.
Any question mentioning hierarchy is always going to be role based ACL
Rule based access control
Uses global rules applied to all users equally
Bell La Padula
Simple security property- not allowed to read up (obvious). “No read up” * Security property-not allowed to write to lower level “ no write down” Strong star (*)- can not read or write to an object of higher/lower sensitivity
DOESNT DEAL WITH COVERT CHANNELS
BIBA
No read down
No write up
- always is write