Access Control
The main objective of the access control process is to ensure that only authorized users are granted access. To achieve this, it is very important for user activities to be uniquely identifiable for accountability purposes. The security manager should be aware of the following categories of access control.
Mandatory Access Control
In mandatory access control (MAC), control rules are governed by an approved policy. Users or data owners cannot modify the access role. MAC ensures that files are shared only with authorized users as per the security classification of the file, and files cannot be shared with unauthorized users.
Discretionary Access Control
In discretionary access control (DAC), control access can be activated or modified by the data owner as per their discretion.
MAC is considered more robust and stringent in terms of information security compared to DAC. To increase the effectiveness of DAC, it should be aligned in accordance with MAC...