208 ◾ Information Security Fundamentals
such as when an ACL is maintained and you must be a member of the group to
access certain information. In this case, the entire group can access the information
and has the same access permissions.
Role-Based Access Control
R-BAC, sometimes referred to as nondiscretionary access control, is a type of access
control in which a user is assigned access based on their job description. is is
a good model for companies where there are frequent personnel changes or for a
bad economy where often consultants are used on a short-term basis in place of
permanent employees. In high turnover environments, users are easily added to
and removed from roles. As explained in “Practical Role-Based Access Control”
(Ga