non-discretionary access control

non-discretionary access control

A means of restricting access to objects based on the sensitivity (as represented by a security label) of the information contained in the objects and the formal authorization (i.e., clearance, formal access approvals, and need-to-know) of subjects to access information of such sensitivity. Mandatory Access Control is a type of nondiscretionary access control.

📚 Reference: NIST SP 800-53 Rev. 4
🏷️ Category: Cybersecurity
📊 Commonality: common