Which access control model uses subject and object labels to enforce access based on a security policy?
Mandatory Access Control assigns sensitivity labels to subjects and objects, and the system enforces access strictly from the security policy rather than owner discretion. This label-based, policy-driven enforcement is the defining mechanism that distinguishes MAC from discretionary or role-based models.
Why this answer
Mandatory Access Control (MAC) enforces access decisions based on security labels assigned to subjects (users/processes) and objects (files/resources). The system, not the user, controls access by comparing these labels against a security policy, such as Bell-LaPadula or Biba. This is why MAC is the correct answer for label-based enforcement.
Exam trap
ISC2 often tests the misconception that ABAC uses labels (since attributes can be labels), but the key distinction is that MAC uses mandatory, system-enforced labels tied to a security policy, whereas ABAC evaluates attribute-based rules dynamically without fixed subject/object labels.
How to eliminate wrong answers
Option A is wrong because Discretionary Access Control (DAC) allows the owner of an object to set permissions at their discretion, using Access Control Lists (ACLs) or owner-based rights, not system-enforced labels. Option B is wrong because Attribute-Based Access Control (ABAC) uses attributes (e.g., user role, time, location) evaluated against policies, but it does not rely on fixed subject/object labels as the primary enforcement mechanism. Option D is wrong because Role-Based Access Control (RBAC) assigns permissions based on predefined roles (e.g., 'admin', 'viewer'), not on security labels that compare subject and object classifications.