ExamChapter 43 min read

Access Control and Identity — Who Can Do What

O
OIYO EditorialContributor
4/8

Authentication vs Authorization

Authentication: Who are you?

Authorization: What may you do?

Accounting: What did you do?


Authentication Factors

FactorMeaningExamples
KnowledgeSomething you knowPassword, PIN
PossessionSomething you haveOTP, smart card, hardware token
InherenceSomething you areFingerprint, iris, face
LocationSomewhere you areIP, GPS
BehaviorHow you actTyping pattern

MFA: Two or more factors from different categories.


Access-Control Models

DAC

The owner decides. Flexible. Easy to misconfigure.

  • File owner: “give a friend read”
  • Examples: Unix file modes, Windows ACLs

MAC

The system decides from security labels. Military environments.

A Secret-labeled file → only Secret-or-higher clearance
Users cannot grant access on their own

RBAC

Permissions attach to roles. The corporate default.

Physician role → patient records
Nurse role → a narrower set of records
Admin role → administrative systems

ABAC

User attributes + resource attributes + environment. Finest grain. Most complex.


Privileged Access Management (PAM)

For admins, DBAs, and other high-privilege accounts:

  • Least privilege: only what the job needs
  • Just-in-time (JIT): privilege only for the window of work
  • Session recording: watch and store privileged sessions
  • Password vault: central admin secrets, automatic rotation

Single Sign-On

Authenticate once, reach many systems.

SAML: XML, enterprise federation.
OAuth 2.0: Delegation — “Sign in with Google.”
OpenID Connect: OAuth 2.0 plus an identity layer.


Key Concept Cards

DAC vs MAC vs RBAC ★★★★★
: DAC = owner (flexible). MAC = labels (military). RBAC = roles (enterprise default).

MFA ★★★★★
: Two or more factor types. Knowledge + possession is the common pair. App/hardware beats SMS.

PAM ★★★★★
: Least privilege, JIT, session recording. Limits insider misuse and stolen admin accounts.


Practice Quiz

Q1. A hospital must keep nurses off records only physicians may see. Which model fits?

RBAC. Bind full record access to the physician role and a narrower set to the nurse role. When staff change, grant or revoke the role — you are not managing every person one ACL at a time.

Q2. Why does least privilege matter most on privileged accounts?

An admin account can reach the whole system. Compromise or misuse is organization-wide. JIT keeps day-to-day work on a normal account and lifts privilege only for a bounded task — which shrinks the attack surface.

O

OIYO Editorial

Editorial Desk

The OIYO editorial desk researches money, law, lifestyle, and self-understanding topics against primary sources and public statistics. Every piece carries source notes and is reviewed on a regular cycle for accuracy and usefulness.