Access Control Models

320 Words2 Pages
Compare and contrast access control models. Control Model | What is it? | Who gives permissions? | Mandatory access controls | Permission to enter a system is kept by the owner. Cannot be given to someone else. | System Owner | Discretionary access controls | The owner of the resource decides who gets in, and changes permissions as needed. Can be given to others. | Creator of resource | Role-based access controls | Access control is determined by the jobs the user is assigned. | Resource owner | Rule-based access controls | A list of rules, maintained by the data owner, determines which users have access to objects | Data Owner | Content-dependent access controls | Access control is based on what is contained in the data. | Access control mechanism | Nondiscretionary access controls | Closely monitored by the security administrator, not the system administrator | Security Administrator | Select an access control model for each of the following scenarios. 1. Shovels and Shingles is a small construction company consisting of 12 computers that have Internet access. a. Content b. Role-based 2. Top Ads is a small advertising company consisting of 12 computers that have Internet access. All employees communicate using smartphones. c. Mandatory d. Discretionary e. Content f. Rule-based 3. NetSecIT is a multinational IT services company consisting of 120,000 computers that have internets access and 45,000 servers. All employees communicate using smartphones and e-mail. Many employees work from home and travel extensively. g. Mandatory h. Role-based i. Rule-based j. Discretionary k. Content 4. Backordered Parts is a defense contractor that builds communications parts for the military. All employees communicate using smartphones and e-mail. l.
Open Document