MAC & RBAC question
Vogon Poet
Member Posts: 291
in Security+
Can anyone help with a question about "rule-base access control"?
I have some sources that lump it under RBAC, and other sources that lump it under MAC. Which is it? Can it be both?
Oddly enough, these are standard study books, like Syngress, ExamCram, & Mike Meyers. You would think that they would agree.
I have some sources that lump it under RBAC, and other sources that lump it under MAC. Which is it? Can it be both?
Oddly enough, these are standard study books, like Syngress, ExamCram, & Mike Meyers. You would think that they would agree.
No matter how paranoid you are, you're not paranoid enough.
Comments
-
sprkymrk Member Posts: 4,884 ■■■□□□□□□□RBAC is the acronym for both Rule Based and Role Based Access Control. MAC is a different category altogether (Mandatory Access Control).
For the purposes of the Security+ exam, don't worry too much about Rule Based Access Controol, except to remember that it is generally used in reference to Firewalls, Routers, and other network devices.
Unless otherwise stated, assume RBAC refers to Role Based Access Control which is considered better security than DAC (Discretionary), but less secure than MAC.All things are possible, only believe. -
Webmaster Admin Posts: 10,292 AdminVogon Poet wrote:Can it be both?
What important to keep in mind, just as with the OSI model, is that these are models. Real systems use characteristics from these models, or a combination of them, but usually don't map exactly to one particular model.Oddly enough, these are standard study books, like Syngress, ExamCram, & Mike Meyers. You would think that they would agree.