Content-dependent access control
Access control in which the decision turns on what the requested object contains, such as the values in a database record, as well as on who is asking.
Content-dependent access control decides whether to allow a request by looking at the data inside the object, not only at the identity of the subject. A database view is the usual illustration. A manager may be allowed to query a salary table but see only the rows whose department field matches their own, while the rest of the table stays hidden.
It is commonly taught beside context-dependent access control, and the two are easy to mix up. A content-dependent rule reads the data; a context-dependent rule reads the circumstances of the request, such as time, location or the order of earlier actions. Both refine a broader model rather than replace it, and both can be written as policy in attribute-based access control, where a property of the object is one attribute among several. The gain is a closer fit to need to know; the cost is processing, because each decision means inspecting content.
Exam relevance: a scenario is likely to describe a restriction and ask which kind of control it shows. A rule that depends on a value inside the record, such as a department code or a classification field, points to content-dependent control. A rule that depends on when, where or in what order access happens points to context-dependent control.