官术网_书友最值得收藏!

Advanced Least Privilege Security concepts

Most operating systems, including Windows NT, use advanced Least Privilege Security concepts as follows:

Discretionary Access Control

Discretionary Access Control (DAC) is where system administrators assign access to a set of objects, such as a directory of files, and allow the user to change the security properties of those files. The user becomes the owner of the directory and can modify the security properties of all files within that directory.

Mandatory Access Control

Mandatory Access Control (MAC) allows system administrators to centrally control the changes users can make to objects they own. MAC helps prevent the flow of sensitive information from a high-privileged account to a lower one.

Mandatory Integrity Control

Windows Vista introduced a form of MAC through Mandatory Integrity Control (MIC) that prevents processes running with a low Integrity Level (IL) from writing to or deleting objects with a higher IL.

Role-based Access Control

Windows Server 2003 included Role-based Access Control (RBAC) that allows system administrators to control access, based on users' organizational roles. Focusing on users' roles rather than objects and resources, as with DAC, is a more natural way for system administrators to control access to data across an organization. DAC enforces basic least privilege concepts to protect operating system files and registry keys using groups, which are collections of users, whereas RBAC roles are collections of permissions.

主站蜘蛛池模板: 连云港市| 沅江市| 咸宁市| 安吉县| 东山县| 射阳县| 临朐县| 南召县| 井研县| 玉山县| 孝感市| 萝北县| 车险| 布尔津县| 永德县| 射洪县| 社旗县| 张家川| 潍坊市| 碌曲县| 博兴县| 黔南| 潮州市| 来安县| 炎陵县| 河北省| 清远市| 酒泉市| 修武县| 镇远县| 外汇| 宁海县| 冷水江市| 遵义县| 宜君县| 元江| 同仁县| 贵定县| 旬邑县| 湟源县| 凤翔县|