| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
5.5.5 MAC/DAC/RBAC (Page 2 of 2) Discretionary Access Control (DAC) DAC uses an access policy that restricts access based on the identity of users and/or groups. DAC is identity-based. Strict DAC does not allow ownership transfer. For example, Bob can create an object (say a spreadsheet). Bob grants access to Ted. Ted cannot grant access to Carol. Being discretionary means you can choose to implement access control, or not IE. Assign permissions and level of access (Read-Write-Execute) to someone else. Contrast this with Mandatory Access Control. MAC is the most stringent of the security controls. Unlike DAC, you don't have a choice about whether or not to allow copying of information. In a MAC, 'everything' and everybody gets a label. This label is called a sensitivity or classification label. This allows for multi-level security policies. That is the ability to handle different clearance levels on a single system. Labels can be created for levels of trust such as:
And, another set of labels such as:
These labels can be combined. For example a User and Sales may be allowed to access another label set such as specifications. While higher authority exists with Accounting and Power User, these labels could be combined to only allow this Labeled Person with an Accounting Label to print to the Labeled Printer Secure Printer from the Labeled File Accounts Receivable. For more information refer to DOD 5200.28-STD447 (Orange Book) __________________ 447. http://www.radium.ncsc.mil/tpep/library/rainbow/5200.28-STD.html
Home - Table Of Contents - Contact Us CertiGuide for Security+ (http://www.CertiGuide.com/secplus/) on CertiGuide.com Version 1.0 - Version Date: November 15, 2004 Adapted with permission from a work created by Tcat Houser et al. CertiGuide.com Version © Copyright 2004 Charles M. Kozierok. All Rights Reserved. Not responsible for any loss resulting from the use of this site. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||