Access Control Flashcards

1
Q

Explain what MAC is and who usually uses it?

A

Mandatory Access Control

Access rights regulated by central authority, based on multiple levels of security.
Operating system constrains ability of subject to access/perform operation on object.
Centrally controlled by security policy admin, users can’t override it.

Usually used by government and military environments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is DAC? Can permissions be passed on with DAC?

A

Discretionary Access Control

Restricting access to objects based on identity of subjects and/or groups.

Subjects with certain access permission is capable of passing permission to another subject (unless restrained by MAC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is RBAC?

Who uses it and what are it’s components?

A

Role-based Access Control
Restricting system access to authorised users.
Policy-neutral Access Control mechanism defined around roles and privileges.
Used by majority of enterprises.
Components:
Role-permissions
User-role
Role-role relationships, makes it simple to perform user assignments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly