官术网_书友最值得收藏!

Advanced Least Privilege Security concepts

Most operating systems, including Windows NT, use advanced Least Privilege Security concepts as follows:

Discretionary Access Control

Discretionary Access Control (DAC) is where system administrators assign access to a set of objects, such as a directory of files, and allow the user to change the security properties of those files. The user becomes the owner of the directory and can modify the security properties of all files within that directory.

Mandatory Access Control

Mandatory Access Control (MAC) allows system administrators to centrally control the changes users can make to objects they own. MAC helps prevent the flow of sensitive information from a high-privileged account to a lower one.

Mandatory Integrity Control

Windows Vista introduced a form of MAC through Mandatory Integrity Control (MIC) that prevents processes running with a low Integrity Level (IL) from writing to or deleting objects with a higher IL.

Role-based Access Control

Windows Server 2003 included Role-based Access Control (RBAC) that allows system administrators to control access, based on users' organizational roles. Focusing on users' roles rather than objects and resources, as with DAC, is a more natural way for system administrators to control access to data across an organization. DAC enforces basic least privilege concepts to protect operating system files and registry keys using groups, which are collections of users, whereas RBAC roles are collections of permissions.

主站蜘蛛池模板: 水富县| 公安县| 左云县| 东乡县| 婺源县| 广南县| 湘潭县| 乌拉特中旗| 潞城市| 睢宁县| 连江县| 盐池县| 东乡县| 上林县| 湟源县| 鸡东县| 鄄城县| 从江县| 凤翔县| 西盟| 介休市| 定远县| 福建省| 台江县| 苍溪县| 桦川县| 隆尧县| 扬中市| 阿鲁科尔沁旗| 电白县| 梓潼县| 花垣县| 永州市| 宁陵县| 上杭县| 页游| 阿图什市| 紫阳县| 华蓥市| 阜宁县| 阿鲁科尔沁旗|