Access control is the heart of Domain 5 and, in many ways, of security itself. Its purpose is to ensure that only authorized subjects can reach objects, and only in the ways they are permitted. A subject is an active entity such as a user, process or device that requests access; an object is the passive resource being accessed, such as a file, database, server, room or application. Every access decision answers the same question: may this subject perform this action on this object right now?
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.