Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
Access control models are methodologies in which admission to physical areas, and more important, computer systems, is managed and organized. Access control, also known as an access policy, is extremely important when it comes to users accessing secure or confidential data. Some organizations also practice concepts such as separation of duties, job rotation, and least privilege. By combining these best practices along with an access control model, a robust plan can be developed concerning how users access confidential data and secure areas of a building.
There are several models for access control, each with its own special characteristics that you should know for the exam. The three most commonly recognized models are discretionary access control (DAC), mandatory access control (MAC), and role-based access control (RBAC). Let’s discuss these now.