Access Control List (ACL)

A list attached to an object that names which subjects may access it and which operations each may perform; the common enforcement mechanism behind discretionary access control.

An access control list is stored with an object, such as a file, share or table, and records which subjects may use it and with which rights, such as read, write or execute. When a subject requests access, the system looks up the object’s list and allows only what an entry permits. Many systems apply implicit deny, so anything not listed is refused.

In terms of the access control matrix, an ACL is one column: one object, every subject’s rights to it. The row view, one subject and every object it can reach, is a capability table. The column view makes it easy to see who can reach an object, and harder to see everything one user can reach. File system ACLs are commonly how discretionary access control is enforced, because the owner edits the list. Routers and firewalls also use the term for ordered rule lists matched against traffic, which is closer to rule-based access control.

Exam relevance: a scenario is likely to describe permissions kept with a resource and ask which mechanism is in use. Candidates are expected to tell an ACL (object-centred, a matrix column) from a capability table (subject-centred, a matrix row), and to recognise that the network sense of the term means ordered rules applied to packets rather than to named users.