0

What's the difference between Non-discretionary access control and Role-based Access Control? In CISSP book both mentioned in the different paragraph as in different entity. But In some other place (Cisco Learning Resource) it is said that,

Non-discretionary access control is also known as RBAC.

So is there any difference between them (if yes then what are they) or they are same?

schroeder
  • 123,438
  • 55
  • 284
  • 319
arif
  • 1,088
  • 13
  • 24

1 Answers1

1

RBAC can be discretionary access control, with anyone in the role granting it to you, or mandatory access, with only the security officer granting the role upon application from a manager.

The latter is more common, so the book probably just conflated the two.

davecb
  • 313
  • 1
  • 6