Access Control and Identity — Who Can Do What
Authentication vs Authorization
Authentication: Who are you?
Authorization: What may you do?
Accounting: What did you do?
Authentication Factors
| Factor | Meaning | Examples |
|---|---|---|
| Knowledge | Something you know | Password, PIN |
| Possession | Something you have | OTP, smart card, hardware token |
| Inherence | Something you are | Fingerprint, iris, face |
| Location | Somewhere you are | IP, GPS |
| Behavior | How you act | Typing pattern |
MFA: Two or more factors from different categories.
Access-Control Models
DAC
The owner decides. Flexible. Easy to misconfigure.
- File owner: “give a friend read”
- Examples: Unix file modes, Windows ACLs
MAC
The system decides from security labels. Military environments.
A Secret-labeled file → only Secret-or-higher clearance
Users cannot grant access on their own
RBAC
Permissions attach to roles. The corporate default.
Physician role → patient records
Nurse role → a narrower set of records
Admin role → administrative systems
ABAC
User attributes + resource attributes + environment. Finest grain. Most complex.
Privileged Access Management (PAM)
For admins, DBAs, and other high-privilege accounts:
- Least privilege: only what the job needs
- Just-in-time (JIT): privilege only for the window of work
- Session recording: watch and store privileged sessions
- Password vault: central admin secrets, automatic rotation
Single Sign-On
Authenticate once, reach many systems.
SAML: XML, enterprise federation.
OAuth 2.0: Delegation — “Sign in with Google.”
OpenID Connect: OAuth 2.0 plus an identity layer.
Key Concept Cards
DAC vs MAC vs RBAC ★★★★★
: DAC = owner (flexible). MAC = labels (military). RBAC = roles (enterprise default).
MFA ★★★★★
: Two or more factor types. Knowledge + possession is the common pair. App/hardware beats SMS.
PAM ★★★★★
: Least privilege, JIT, session recording. Limits insider misuse and stolen admin accounts.
Practice Quiz
Q1. A hospital must keep nurses off records only physicians may see. Which model fits?
RBAC. Bind full record access to the physician role and a narrower set to the nurse role. When staff change, grant or revoke the role — you are not managing every person one ACL at a time.
Q2. Why does least privilege matter most on privileged accounts?
An admin account can reach the whole system. Compromise or misuse is organization-wide. JIT keeps day-to-day work on a normal account and lifts privilege only for a bounded task — which shrinks the attack surface.
OIYO Editorial
Editorial DeskThe OIYO editorial desk researches money, law, lifestyle, and self-understanding topics against primary sources and public statistics. Every piece carries source notes and is reviewed on a regular cycle for accuracy and usefulness.