Object (access control)

In access control, the passive resource being protected, such as a file, database record, service, device or room, which a subject requests access to.

In access control, an object is the passive entity that holds or represents something worth protecting: a file, a database record, an application interface, or, for physical controls, a room. The active entity asking for access is the subject, usually a user or process. An access control decision is framed as a subject requesting an operation (read, write, execute, delete) on an object, which a reference monitor mediates.

The subject and object roles describe a relationship, not a fixed type of thing. A program stored on disk is an object that an administrator can update; the same program running as a process becomes a subject when it opens a file. Models record the pairing in different ways: an access control matrix has subjects as rows and objects as columns, an access control list is kept with the object and lists who may do what to it, and a capability table is kept with the subject. Object-oriented programming uses the word in a separate sense.

Exam relevance: a scenario is likely to ask which element is the subject and which the object. Candidates are expected to identify the object as the passive resource acted upon, and to recognise that one entity can be a subject in one access and an object in another.