You are currently viewing CISSP certification: MAC (Mandatory Access Control)

CISSP certification: MAC (Mandatory Access Control)

MAC (Mandatory Access Control): Often used when Confidentiality is most important.

Almost always used in the military or in organizations where confidentiality is very important, rarely used in the private sector (unless in defense contracting).

  • Access to an object is determined by labels and clearance
  • Labels: Objects have Labels assigned to them, the subjects clearance must dominate the objects label.
    • The label is used to allow Subjects with the right clearance access them.
    • Labels are often more granular than just “Top Secret”, they can be “Top Secret – Nuclear”.
  • Clearance: Subjects have Clearance assigned to them.
    • Based on a formal decision on a subjects current and future trustworthiness.

The higher the clearance the more in depth the background checks should be.

Thor Pedersen

IT, information security, and project management trainer Best selling CISSP. CISM, and PMP instructor on Udemy. CISSP, CISM, C|EH, CDPSE, PMP, 2x CCNP, CompTIA Security+, SCP, 3x CCNA, et. Al.