Non-discretionary access control
Any access control approach in which a central authority or system policy, not the owner of a resource, decides who may access it; the opposite of discretionary access control.
Non-discretionary access control is the family of access control approaches in which the owner of a resource does not decide who may use it. A central authority sets the policy and the system enforces it, and an individual user does not pass access on at will. It is defined by contrast with discretionary access control (DAC), where the owner grants and revokes access on their own judgement.
Study sources draw the boundary in different places. Some older sources use the term almost as a synonym for role-based access control, because roles are defined centrally. Others use it as an umbrella over every centrally administered model, placing RBAC, rule-based access control, attribute-based access control and mandatory access control beneath it, while some keep MAC as a category of its own. What they share is the point that matters: centrally managed access resists the drift that owner discretion allows.
Exam relevance: a scenario is likely to describe who decides access. If the resource owner decides, it is discretionary; if a central authority, role definition or system rule decides and the owner cannot override it, it is non-discretionary. Candidates are expected to reason from that distinction rather than rely on one source’s list of which models fall under the term.