Discretionary Protection - according to the Trusted Computer System Evaluation Criteria Criteria level marked C1. Provides elementary security for users working in a multi-user environment and processing data of equal security level. C1 systems use hardware or software mechanisms to identify and authorize users. The system protects identification and passwords from unauthorized access. Identification of users should be used in each access mode of the resource. Each user has full control over the objects that own it. Most unix systems are included in this class.
Unlike MAC, a user who has specific access rights to objects can give it to other users. DAC allows the user to fully set permissions to access their own resources. Existing DAC implementations can additionally control the above mentioned laws.
Privileges are most commonly written in the form of ACLs assigned to individual objects.
Basic security model for most operating systems. User and process objects inherit access rights by default.
wiki
Comments
Post a Comment