home/glossary/Discretionary access control

Discretionary access control

nounverified·updated May 9, 2026

A means of restricting access to objects (e.g., files, data entities) based on the identity and need-to-know of subjects (e.g., users, processes) and/or groups to which the object belongs. The controls are discretionary in the sense that a subject with a certain access permission is capable of passing that permission (perhaps indirectly) on to any other subject (unless restrained by mandatory access control).

polysemousMWENISTIR 7298: Glossary of Key Information Security Terms, Revision 2

Senses

SANS Glossary of Security Terms

Discretionary Access Control consists of something the user can manage, such as a document password.

ISACA Cybersecurity Glossary

A means of restricting access to objects based on the identity of subjects and/or groups to which they belong Scope Note: The controls are discretionary in the sense that a subject with a certain access permission is capable of passing that permission (perhaps indirectly) on to any other subject.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2

The basis of this kind of security is that an individual user, or program operating on the user’s behalf, is allowed to specify explicitly the types of access other users (or programs executing on their behalf) may have to information under the user’s control.

Classifications

Entity Type

Control95%rule-basedr:entity.control.safeguard.v1
?unassignedlast reviewed

Sensitivity

90%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Information Class

90%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Variants

acronym
DAC
plural
Discretionary access controls
possessive
Discretionary access control's
pluralpossessive
Discretionary access controls'