What does access control determine?
Access control determines which subjects may perform which actions on which resources, and under what conditions.
Study 6 Access Control with 12 free online flashcards. Review key terms, definitions, and concepts with this interactive flashcard deck.
What does access control determine?
Access control determines which subjects may perform which actions on which resources, and under what conditions.
What is authorization?
Authorization is the decision to permit or deny a particular request.
Who controls access in discretionary access control (DAC)?
In DAC, resource owners can grant or revoke access, often using permissions or access-control lists.
What does an access-control list (ACL) record?
An access-control list records which entities may access a resource and which access modes they have.
How does mandatory access control (MAC) govern access?
MAC uses a central policy based on classifications or labels; users generally cannot override it by changing resource permissions.
How does role-based access control (RBAC) assign permissions?
RBAC assigns permissions to job-function roles, and users receive those permissions through their role assignments.
What information can attribute-based access control (ABAC) evaluate?
ABAC evaluates attributes of the subject, resource, requested action, and possibly the environment to decide access.
What is the principle of least privilege?
Least privilege means granting users and processes only the access needed for their assigned tasks.
What does “deny by default” mean?
Deny by default means granting access only when an applicable policy explicitly allows it.
What is the purpose of separation of duties?
Separation of duties prevents one person from completing a sensitive process alone, such as preparing and approving the same payment.
When should authorization be enforced?
Authorization should be checked on every relevant request, including requests for individual records or functions—not only at sign-in.
How should organizations respond to changing access needs?
Review assignments periodically, remove unnecessary access, update permissions when duties change, and promptly revoke access that is no longer needed.