Discretionary access control
A means of restricting access to objects (e.g., files, data entities) based on the identity and need-to-know of subjects (e.g., users, processes) and/or groups to which the object belongs. The controls are discretionary in the sense that a subject with a certain access permission is capable of passing that permission (perhaps indirectly) on to any other subject (unless restrained by mandatory access control).
Senses
Discretionary Access Control consists of something the user can manage, such as a document password.
A means of restricting access to objects based on the identity of subjects and/or groups to which they belong Scope Note: The controls are discretionary in the sense that a subject with a certain access permission is capable of passing that permission (perhaps indirectly) on to any other subject.
The basis of this kind of security is that an individual user, or program operating on the user’s behalf, is allowed to specify explicitly the types of access other users (or programs executing on their behalf) may have to information under the user’s control.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- acronym
- DAC
- plural
- Discretionary access controls
- possessive
- Discretionary access control's
- pluralpossessive
- Discretionary access controls'