Home > Glossary > CCSP > Mandatory Access Control (MAC)

📖 What is Mandatory Access Control (MAC)?

Mandatory Access Control (MAC) is a strict access control system where access rights are regulated by a central authority based on multiple levels of security. Users are granted access to objects based on their clearance level and the object's classification label, preventing data leakage.

🥋 Sensei Says:

"Think 'Military' for MAC. It is the most restrictive model and relies on labels and clearances, not user discretion."

📚 Certification: CCSP (CCSP)

🔑 What are the Key Concepts of Mandatory Access Control (MAC)?

  • Labels and Clearances: MAC assigns security labels to objects and clearance levels to subjects, ensuring access is granted only when the subject's clearance matches the object's label.
  • Centralized Administration: Access policies are defined by a central security authority, meaning resource owners cannot change permissions or grant access to other users at their own discretion.
  • Bell-LaPadula Model: A MAC implementation focused on confidentiality that enforces 'no read up' and 'no write down' rules to prevent sensitive information from leaking to lower levels.
  • Biba Integrity Model: A MAC implementation focused on integrity that enforces 'no read down' and 'no write up' rules to prevent low-integrity data from contaminating high-integrity systems.
  • Non-Discretionary Nature: MAC is the most restrictive model because it removes user control over data access, making it the standard for military and high-security government environments.

🎯 How does Mandatory Access Control (MAC) appear on the CCSP Exam?

You may be asked to identify the most appropriate access control model for a government cloud deployment that requires strict, non-discretionary data isolation based on security clearances.

A scenario might describe a system where a user is forbidden from writing data to a lower security level to prevent leakage; you must identify this as a MAC Bell-LaPadula implementation.

Expect questions comparing MAC and DAC, where you must determine which model prevents a file owner from granting access to another user without central administrative approval.

❓ Frequently Asked Questions

How does MAC differ from Discretionary Access Control (DAC) in a cloud context?

In DAC, the resource owner manages permissions. In MAC, the system policy—defined by a central authority—overrides the owner's wishes, providing tighter security and preventing accidental or malicious over-sharing of data.


Is MAC commonly used in standard public cloud environments?

Standard public clouds primarily use RBAC. However, MAC is used in specialized government clouds or via OS-level controls like SELinux to provide hardened isolation for highly sensitive workloads.


Which MAC model should I choose for a system prioritizing data integrity over confidentiality?

You should choose the Biba model. While Bell-LaPadula protects confidentiality (secrets), Biba protects integrity by ensuring that high-level data is not corrupted by information from lower-integrity sources.

Related Terms from CCSP

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Mandatory Access Control (MAC)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium