Access control model

The approach a system uses to decide who may access what, and who controls those decisions: owner-set (DAC), label-based (MAC), role-based, rule-based, attribute-based or risk-based.

An access control model describes how authorisation decisions are reached and where the authority to set them sits. The ISC2 exam outline, under 5.4, lists role-based, rule-based, mandatory, discretionary, attribute-based and risk-based access control. They differ in the basis for the decision: the owner’s choice in discretionary access control, labels and clearances in mandatory access control, job function in role-based access control, system-wide conditions in rule-based access control, combinations of subject, object and environment attributes in attribute-based access control, and a calculated risk score in risk-based access control.

A useful first split is who holds the authority. Under DAC the resource owner grants access; in the other models a central policy decides, which is why study sources commonly group them as non-discretionary. The model is the policy approach; mechanisms such as an access control list or a policy decision point are how it is enforced. Access control models are also commonly confused with formal security models such as Bell-LaPadula, which state rules a system must preserve, such as confidentiality or integrity, rather than describing how an organisation assigns access.

Exam relevance: a scenario is likely to describe how access is granted in an organisation and ask which model fits. Candidates are expected to read for the decision basis: owner, label, job, blanket rule, attribute combination or risk signal.