74.0k views
4 votes
Discretionary access control is an approach whereby the organization specifies use of resources based on the assignment of data classification schemes to resources and clearance levels to users.

User Oliland
by
6.4k points

2 Answers

1 vote

Final answer:

Discretionary Access Control (DAC) in an organizational context involves assigning data classifications and user clearances to manage resource access. This differs from non-defense discretionary spending and categorical grants, which pertain to government budgeting and strict fund usage respectively.

Step-by-step explanation:

Discretionary Access Control (DAC) relates to how an organization regulates access to its resources. This approach involves assigning data classification schemes and clearance levels to determine who can use certain resources. In comparison to DAC, non-defense discretionary spending involves funding for the executive departments and independent agencies, which includes both mandatory and discretionary spending. The discretionary budget authority is established by Congress on an annual basis.

For instance, in 2016, the federal government spent roughly $600 billion on Cabinet Departments and Agencies, which constituted around 16 percent of budgeted expenditures or about 3.3 percent of GDP. Notably, spending for these functions is below the 2010 peak of $658 billion.

Another concept, a categorical grant, is a federal transfer meant to limit the recipients' discretion in the use of funds, where they are subject to strict administrative criteria. This type of grant serves to direct funds for specific purposes and ensure compliance with federal guidelines, much like how DAC specifies access to information based on classification and clearance.

User Visal Rajapakse
by
5.4k points
5 votes

Answer:

This statement is false. This is the work of Mandatory Access controls (MACs)

Step-by-step explanation:

Discretionary Access Control (DACL) is an example of Access Control Model (ACL) found in objects of a data user in a computer system. They are security descriptors that issue a list of permissions to users, i.e. who has permissions to access an object. It is discretionary as the name suggest to mean which users have permissions to what files on a windows or linux environment.

On the other hand, Mandatory Access controls (MACs) is an approach whereby the organization specifies the use of resources based on the assignment of data classification schemes to resources and clearance levels to users. It is non-discretionary and is based on how the operating system makes decisions on a security label system. The operating systems grants or disallow access rather than the data owners. They are used so much where classification and confidentiality is of utmost importance

User Nastaran Mohammadi
by
5.4k points