Access control model categories analysis with respect to the defined criteria
| Criteria | OSA | MsR | Roles | Content | Context |
|---|---|---|---|---|---|
| Authorization strategy | DAC | MAC | Hybrid | Hybrid | Hybrid |
| Granularity of control | L | La | M | H | H |
| Least privilege principal support | L | M | M | H | Ob |
| Dynamic authorization | ✗ | ✗ | ✓ | ✓ | ✓ |
| Separation of duty | ✗ | Oc | ✓ | ✓ | ✓ |
| Vulnerable to attacks | ✓ | ✓ | ✗ | ✗ | ✗ |
| Bypass | ✗ | ✗ | ✗ | ✗ | ✓ |
| Conflict resolution or prevention | ✗ | ✗ | ✗ | Od | Ob |
| Operational/situational awareness | ✗ | ✗ | ✓ | ✓ | ✓ |
| Privileges/capabilities discovery | ✓ | ✗ | ✓ | Oe | ✗ |
| Criteria | OSA | MsR | Roles | Content | Context |
|---|---|---|---|---|---|
| Authorization strategy | DAC | MAC | Hybrid | Hybrid | Hybrid |
| Granularity of control | L | La | M | H | H |
| Least privilege principal support | L | M | M | H | O |
| Dynamic authorization | ✗ | ✗ | ✓ | ✓ | ✓ |
| Separation of duty | ✗ | O | ✓ | ✓ | ✓ |
| Vulnerable to attacks | ✓ | ✓ | ✗ | ✗ | ✗ |
| Bypass | ✗ | ✗ | ✗ | ✗ | ✓ |
| Conflict resolution or prevention | ✗ | ✗ | ✗ | O | O |
| Operational/situational awareness | ✗ | ✗ | ✓ | ✓ | ✓ |
| Privileges/capabilities discovery | ✓ | ✗ | ✓ | O | ✗ |
Notes:
aExcept the MLS database model;
Depends on the underlying access control model;
Supported by the Chinese-Wall model;
Supported by ABAC and EBAC models; and
Supported by the VBAC model
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.