003 - Cybersecurity Fundamentals Access Control Concepts
003 - Cybersecurity Fundamentals Access Control Concepts
Passwords
Types of logical access controls Biometrics (implemented on a system, such as a
smartphone or laptop)
include:
Badge/token readers connected to a system
Discretionary Access
Control
Specifies that a subject who has been granted access to
information can do one or more of the following:
• Pass the information to other subjects or objects
• Grant its privileges to other subjects
• Change security attributes on subjects, objects,
information systems or system components
• Choose the security attributes to be associated with newly
created or revised objects; and/or
• Change the rules governing access control; mandatory
access controls restrict this capability
Rule-based access control systems are usually a form of DAC.
Mandatory Access Control