Access control decides who gets in and what they can touch. A hospital clerk needs patient records to schedule appointments. She does not need the billing system or the research database. Access control enforces that difference. Without it, every account becomes a potential path to everything.
The mechanics vary. Role-based access control assigns permissions by job title. A nurse role gets one set of rights, a doctor role gets another. Attribute-based systems go further, weighing department, time of day, location, and device. A doctor on a hospital laptop at 2 a.m. may pass. The same doctor on an unrecognized device from another country may not. Multifactor authentication adds a second check at login. The principle underneath all of it is least privilege: give each account the minimum it needs, nothing more.
Common access control models
- Discretionary — owners set permissions on their own files
- Mandatory — system-wide labels, common in government and military settings
- Role-based — permissions tied to job functions
- Attribute-based — decisions based on many contextual factors
Access reviews matter as much as the initial setup. People change roles. Contractors leave. Old accounts linger with permissions nobody remembers granting. A quarterly review catches what automation misses. Attackers count on that neglect.
Comments
No comments yet. Be the first to share a thought.
Leave a comment