Sunday, 4 October 2026

DAC vs MAC vs RBAC vs ABAC: Difference Between Access Control Models

DAC vs MAC vs RBAC vs ABAC

Access control is one of the most important concepts in cybersecurity and information security. It determines which users, devices or systems are allowed to access particular resources and what operations they are permitted to perform.

Four important access control models commonly discussed in computer science and cybersecurity are DAC, MAC, RBAC and ABAC.

  • DAC: Discretionary Access Control
  • MAC: Mandatory Access Control
  • RBAC: Role-Based Access Control
  • ABAC: Attribute-Based Access Control
Easy way to remember:
DAC = Owner decides
MAC = Policy/classification decides
RBAC = Role decides
ABAC = Attributes and policies decide

Quick Difference Between DAC, MAC, RBAC and ABAC

Model Basic Idea Access Depends Mainly On
DAC Resource owners control access. Owner-defined permissions
MAC Access is controlled by centrally defined security policies. Security labels and clearance
RBAC Permissions are assigned to roles. User's role
ABAC Access is determined using attributes and policies. User, resource, action and environmental attributes

What Is Access Control?

Access control is the process of deciding whether a subject should be allowed to perform a particular action on a particular resource.

A simplified access-control decision can be represented as:

Subject → Request → Policy Evaluation → Access Decision → Resource

For example, a student may be allowed to view a course document but not modify or delete it. An administrator may have additional permissions.

Authentication vs Authorization

Access control is closely related to authentication and authorization, but these terms are not identical.

Concept Meaning Example
Authentication Determines who the user or entity is. Logging in with credentials or a passkey.
Authorization Determines what an authenticated entity is allowed to do. Allowing a student to view but not delete a record.
Access Control Mechanisms and policies used to enforce access decisions. Allowing or denying access to a file or application.

1. What Is DAC?

DAC stands for Discretionary Access Control.

In DAC, the owner of a resource generally has discretion over who can access the resource and what permissions those users receive.

The resource owner can grant or revoke permissions according to the access-control mechanism being used.

Simple DAC Example

Suppose a user creates a file called project-report.pdf. Under a DAC-style permission system, the owner may give another user permission to read the file.

Resource Owner → Grants Permission → Other User → Access Resource

Characteristics of DAC

  • Resource owners have significant control over permissions.
  • Permissions can often be granted or revoked by the owner.
  • Access-control lists are commonly associated with DAC.
  • It is flexible and relatively easy to understand.
  • It can become difficult to manage in very large environments.

DAC Advantages

  • Flexible permission management.
  • Simple concept.
  • Users can share resources according to permitted rules.
  • Suitable for many general-purpose operating-system environments.
  • Easy to implement for relatively small environments.

DAC Limitations

  • Users may unintentionally grant access to sensitive resources.
  • Large numbers of individual permissions can become difficult to manage.
  • Centralized enforcement may be weaker than in mandatory models.
  • Permission inheritance and sharing can create complex access relationships.

2. What Is MAC?

MAC stands for Mandatory Access Control.

In MAC, access decisions are controlled by centrally defined security policies rather than being left primarily to individual resource owners.

Resources and subjects can be assigned security labels or classifications, and access is determined according to the applicable security policy.

Simple MAC Example

Consider an environment where documents have classifications such as:

  • Public
  • Confidential
  • Secret
  • Top Secret

A user may have an approved clearance level. The security policy determines whether that user can access a particular classified resource.

User Clearance + Resource Classification + Security Policy → Access Decision

Characteristics of MAC

  • Access is controlled by centrally managed policies.
  • Security labels or classifications can be used.
  • Resource owners generally cannot freely override mandatory restrictions.
  • It is suitable for environments requiring strict information control.
  • It can be more restrictive and complex than DAC.

MAC Advantages

  • Strong centralized control.
  • Useful for highly sensitive information.
  • Reduces arbitrary permission sharing.
  • Supports strict security policies.
  • Suitable for environments with formal security classifications.

MAC Limitations

  • More complex to administer.
  • Less flexible for ordinary users.
  • Requires careful policy design.
  • Changing security requirements can require centralized policy changes.

3. What Is RBAC?

RBAC stands for Role-Based Access Control.

In RBAC, permissions are assigned to roles, and users are assigned to those roles.

Instead of individually assigning every permission to every user, administrators can define roles such as:

  • Student
  • Teacher
  • Manager
  • Accountant
  • Administrator

Each role receives an appropriate set of permissions.

Simple RBAC Example

User → Assigned Role → Role Permissions → Resource Access

For example, a university application could define:

Role Possible Permissions
Student View courses, submit assignments, view own results
Teacher View courses, manage assigned course material, evaluate assignments
Administrator Manage users, roles and system configuration

Characteristics of RBAC

  • Permissions are grouped into roles.
  • Users receive permissions through assigned roles.
  • It simplifies administration in organizations.
  • Role hierarchies can be supported.
  • Separation-of-duty policies can be implemented.

RBAC Advantages

  • Easy to manage in organizations with clearly defined job functions.
  • Reduces repetitive permission assignment.
  • Supports least privilege when roles are designed correctly.
  • Can simplify employee onboarding and offboarding.
  • Useful for enterprise applications.

RBAC Limitations

  • Too many roles can create role explosion.
  • Very dynamic access requirements can be difficult to express using roles alone.
  • Role design requires careful planning.
  • Users with multiple responsibilities may require multiple roles.

4. What Is ABAC?

ABAC stands for Attribute-Based Access Control.

ABAC makes access decisions using attributes associated with the subject, resource, action and environment, together with defined policies.

Examples of attributes include:

  • User department
  • User job title
  • User clearance
  • Resource classification
  • Resource owner
  • Requested action
  • Device type
  • Device security status
  • Location
  • Time
  • Network context

Simple ABAC Example

Suppose a company allows employees to access a sensitive application only when:

  • The employee belongs to the Finance department.
  • The employee has the required clearance.
  • The device meets security requirements.
  • The requested action is permitted.
  • The request occurs during an approved condition.
User Attributes + Resource Attributes + Action + Environment + Policy → Decision

Characteristics of ABAC

  • Uses attributes rather than relying only on roles.
  • Can support highly detailed policies.
  • Can consider environmental context.
  • Useful for dynamic access decisions.
  • Can integrate with identity and security systems.

ABAC Advantages

  • Highly flexible.
  • Supports fine-grained access control.
  • Can handle dynamic conditions.
  • Can reduce dependence on large numbers of roles.
  • Useful for cloud and distributed environments.

ABAC Limitations

  • Policy design can be complex.
  • Large numbers of attributes can make administration difficult.
  • Policy evaluation may require more sophisticated infrastructure.
  • Incorrect or inconsistent attribute information can produce incorrect access decisions.

DAC vs MAC vs RBAC vs ABAC: Detailed Parameter-Based Comparison

Parameter DAC MAC RBAC ABAC
Full Form Discretionary Access Control Mandatory Access Control Role-Based Access Control Attribute-Based Access Control
Main Basis Resource ownership Security policy and labels Roles Attributes and policies
Who Determines Access? Usually the resource owner within system rules Central security policy Administrators through role definitions Policy rules using attributes
Permission Assignment Directly to users/groups/resources According to mandatory policy To roles Determined dynamically by policies
User Role Required? No No Yes Not necessarily
Security Labels Not required Commonly used Not required Can be used as attributes
Attributes Not the primary basis Labels/clearance are central Role is the main abstraction Central to access decisions
Flexibility High Lower High for role-oriented organizations Very high
Centralization Lower High High High through policy management
Fine-Grained Control Moderate High High Very high
Dynamic Access Limited Limited to policy model Moderate Excellent
Administration Can become difficult at scale Centralized but complex Generally manageable with good role design Complex policy administration
Scalability Moderate Good for controlled environments Very good for role-oriented organizations Very good when properly designed
User Control Relatively high for resource owners Very limited Limited to assigned roles Limited by policy evaluation
Policy Complexity Low to moderate High Moderate High
Typical Environment General-purpose systems and file sharing Highly controlled environments Business and enterprise applications Cloud, enterprise and context-aware systems
Best Suited For Flexible resource sharing Strict information classification Organizations with defined job roles Complex and dynamic access requirements
Major Risk Improper permission sharing Complexity and rigidity Role explosion Policy and attribute complexity

DAC vs MAC

Parameter DAC MAC
Control Discretionary Mandatory
Decision Authority Resource owner within system constraints Central security policy
User Permission Changes May be allowed according to owner permissions Restricted by policy
Security Classification Not essential Commonly important
Flexibility Higher Lower
Control Strength Generally lower Generally stronger for strict environments

RBAC vs ABAC

Parameter RBAC ABAC
Decision Basis Role Attributes and policies
Example Manager can approve expenses. Finance employee can approve an expense only under specified policy conditions.
Dynamic Context Limited unless supplemented by other mechanisms Strong support
Policy Granularity Role-oriented Highly fine-grained
Administration Usually simpler Usually more complex
Role Explosion Risk Yes Can reduce the need for many specialized roles
Best Use Stable organizational responsibilities Dynamic and context-sensitive access

DAC vs MAC vs RBAC vs ABAC: Real-World Style Examples

DAC Example

A document owner shares a file with another user and grants read permission. The owner later revokes that permission.

MAC Example

A highly sensitive organization classifies information and permits access only when the subject's clearance and the resource classification satisfy the security policy.

RBAC Example

An organization creates an HR Manager role with permissions to manage employee records. Employees assigned to that role receive the associated permissions.

ABAC Example

An organization permits access to a sensitive application when the user belongs to a particular department, has the required clearance, uses an approved device and satisfies the applicable environmental conditions.

Access Control Models and Least Privilege

Least privilege means providing a subject with only the permissions needed to perform its authorized tasks.

All four access-control models can be designed to support least privilege, but the way they implement it differs.

Model How Least Privilege Can Be Applied
DAC Owners grant only required permissions.
MAC Central policy restricts access according to classification and clearance.
RBAC Roles are designed with only required permissions.
ABAC Policies evaluate detailed conditions and attributes to grant only required access.

Access Control Models and Separation of Duties

Separation of duties is a security principle in which critical activities are divided between different users or roles to reduce the risk of unauthorized actions.

RBAC is particularly useful for implementing separation-of-duty policies because organizations can define different roles for different responsibilities.

ABAC can also express more detailed conditions when combined with suitable policy mechanisms.

Which Access Control Model Is More Secure?

There is no universal answer that one model is always the most secure. Security depends on the environment, policy design, implementation, administration and monitoring.

A model that is appropriate for a highly classified environment may not be the most practical choice for a normal business application.

Requirement Potentially Suitable Model
Flexible resource ownership DAC
Strict security classification MAC
Organization based on job functions RBAC
Highly dynamic, context-aware decisions ABAC

Advantages and Disadvantages at a Glance

Model Major Advantages Major Disadvantages
DAC Flexible, simple, convenient sharing Permission sprawl and accidental sharing
MAC Strong centralized security control Complex and less flexible
RBAC Easy organizational administration and role reuse Role explosion and limited context sensitivity
ABAC Fine-grained and dynamic access decisions Complex policy and attribute management

Common Terms Related to Access Control

Subject

An entity requesting access, such as a user, process or device.

Object

A resource being accessed, such as a file, database record or application.

Permission

An authorization to perform a particular operation on a resource.

Policy

A rule or collection of rules that determines how access should be granted or denied.

Role

A logical collection of permissions representing a responsibility or job function.

Attribute

A characteristic used by an access-control policy, such as department, clearance, resource type, location or device status.

Common Mistakes Students Make

  • Thinking authentication and authorization are the same.
  • Thinking RBAC means that users themselves directly receive every permission.
  • Assuming MAC means "Mac computer" rather than Mandatory Access Control.
  • Thinking ABAC uses only user attributes.
  • Assuming DAC always means insecure.
  • Assuming ABAC is always better than RBAC.
  • Confusing security labels in MAC with ordinary roles in RBAC.

Exam-Oriented Questions

What is DAC?

DAC is an access-control model in which resource owners generally have discretion over permissions granted to other subjects.

What is MAC?

MAC is an access-control model in which access is determined by centrally defined mandatory security policies, often involving classifications and clearances.

What is RBAC?

RBAC is an access-control model in which permissions are assigned to roles and users obtain permissions through their assigned roles.

What is ABAC?

ABAC is an access-control model in which policies evaluate attributes of subjects, resources, actions and/or environmental conditions to make access decisions.

Which model is based on roles?

RBAC — Role-Based Access Control.

Which model is based on attributes?

ABAC — Attribute-Based Access Control.

Which model gives resource owners discretion?

DAC — Discretionary Access Control.

Which model commonly uses security classifications?

MAC — Mandatory Access Control.

Frequently Asked Questions

What is the main difference between DAC and MAC?

DAC gives resource owners discretion over permissions, whereas MAC relies on mandatory centrally controlled security policies.

What is the main difference between RBAC and ABAC?

RBAC primarily makes access decisions through roles, while ABAC uses attributes and policies to make potentially more detailed and dynamic decisions.

Is RBAC easier than ABAC?

RBAC is often simpler when organizational permissions map cleanly to job roles. ABAC can provide more flexibility but usually requires more complex policy and attribute management.

Can DAC be used with groups?

Yes. Many DAC implementations can use users and groups when assigning permissions, depending on the system.

Does MAC allow users to change permissions freely?

No. The defining characteristic of MAC is that access is controlled by mandatory security policies rather than being freely controlled by individual resource owners.

What is role explosion in RBAC?

Role explosion occurs when an organization creates an excessive number of specialized roles because its access requirements become increasingly detailed.

Why is ABAC useful for dynamic access control?

ABAC can evaluate multiple attributes and contextual conditions, allowing policies to make access decisions that can change according to the circumstances of a request.

Can organizations combine access-control models?

Yes. Real systems can use multiple mechanisms and policy approaches together. The appropriate architecture depends on security requirements and the technologies being used.

Short Exam Revision

DAC: Owner decides access.

MAC: Mandatory security policy decides access.

RBAC: Role decides permissions.

ABAC: Attributes and policies decide access.

One-Line Difference

DAC is owner-controlled, MAC is policy/classification-controlled, RBAC is role-controlled, and ABAC is attribute-and-policy-controlled access control.

Conclusion

DAC, MAC, RBAC and ABAC are four important access-control models used to control access to information and computing resources.

DAC provides flexibility by allowing resource owners to manage permissions. MAC provides strict centralized control through mandatory security policies. RBAC simplifies enterprise permission management by assigning permissions to roles. ABAC provides highly flexible and fine-grained decisions by evaluating attributes and policies.

For exam preparation, remember the four keywords: Owner → Classification → Role → Attribute.

No comments:

Post a Comment