Access Control Flashcards
Explain what MAC is and who usually uses it?
Mandatory Access Control
Access rights regulated by central authority, based on multiple levels of security.
Operating system constrains ability of subject to access/perform operation on object.
Centrally controlled by security policy admin, users can’t override it.
Usually used by government and military environments.
What is DAC? Can permissions be passed on with DAC?
Discretionary Access Control
Restricting access to objects based on identity of subjects and/or groups.
Subjects with certain access permission is capable of passing permission to another subject (unless restrained by MAC)
What is RBAC?
Who uses it and what are it’s components?
Role-based Access Control
Restricting system access to authorised users.
Policy-neutral Access Control mechanism defined around roles and privileges.
Used by majority of enterprises.
Components:
Role-permissions
User-role
Role-role relationships, makes it simple to perform user assignments.