Discretionary access control

From WikiMD's Wellness Encyclopedia

Discretionary Access Control (DAC) is a type of access control system that restricts access to objects based on the identity of subjects and/or groups to which they belong. The controls are discretionary in the sense that a subject with a certain access permission is capable of passing that permission (directly or indirectly) to any other subject.

Overview[edit | edit source]

In a DAC model, the owner of the protected system, data, or resource sets the policies defining who can access it. This model is commonly used in operating systems and database management systems.

Key Concepts[edit | edit source]

  • Subjects: Entities (such as users or processes) that request access to objects.
  • Objects: Resources (such as files, databases, or devices) that are being accessed.
  • Permissions: The types of access granted to subjects, such as read, write, execute, or delete.

Advantages[edit | edit source]

  • Flexibility: Owners can easily change access permissions.
  • Simplicity: Easy to implement and understand.

Disadvantages[edit | edit source]

  • Security Risks: Since permissions can be easily transferred, it can lead to unauthorized access.
  • Lack of Central Control: Difficult to enforce organization-wide security policies.

Comparison with Other Models[edit | edit source]

DAC is often compared with other access control models such as Mandatory Access Control (MAC) and Role-Based Access Control (RBAC). Unlike DAC, MAC does not allow users to pass permissions to others, and RBAC assigns permissions based on roles rather than individual users.

Applications[edit | edit source]

DAC is widely used in various systems, including:

Related Pages[edit | edit source]

See Also[edit | edit source]

Template:Access control models

WikiMD
Navigation: Wellness - Encyclopedia - Health topics - Disease Index‏‎ - Drugs - World Directory - Gray's Anatomy - Keto diet - Recipes

Search WikiMD

Ad.Tired of being Overweight? Try W8MD's physician weight loss program.
Semaglutide (Ozempic / Wegovy and Tirzepatide (Mounjaro / Zepbound) available.
Advertise on WikiMD

WikiMD's Wellness Encyclopedia

Let Food Be Thy Medicine
Medicine Thy Food - Hippocrates

WikiMD is not a substitute for professional medical advice. See full disclaimer.
Credits:Most images are courtesy of Wikimedia commons, and templates Wikipedia, licensed under CC BY SA or similar.

Contributors: Prab R. Tumpati, MD