Home > Glossary > Certified in Cybersecurity > Mandatory Access Control (MAC)

📖 What is Mandatory Access Control (MAC)?

Mandatory Access Control (MAC) is a strict access control system where the operating system restricts the ability of a subject to access or perform operations on an object. Access is based on security labels and clearances assigned by a central authority.

🥋 Sensei Says:

"Think of this as the 'military model.' It is the most restrictive access control type and does not allow resource owners to change permissions at their own discretion."

📚 Certification: Certified in Cybersecurity (CC)

🔑 What are the Key Concepts of Mandatory Access Control (MAC)?

  • Centralized Administration: Access policies are managed by a central security authority, removing the ability for individual resource owners to modify permissions at their own discretion.
  • Security Labels and Clearances: Subjects are assigned clearance levels and objects are assigned security labels; access is granted only if the subject's clearance matches the object's label.
  • Non-Discretionary Nature: Unlike DAC, MAC prevents users from granting access to their own files, which significantly reduces the risk of accidental or malicious data leakage.
  • Lattice-Based Model: MAC often employs a lattice structure to define the flow of information, ensuring data only moves between authorized security levels to maintain confidentiality.
  • High-Security Implementation: Due to its rigidity and administrative overhead, MAC is primarily used in military, intelligence, and highly regulated government environments.

🎯 How does Mandatory Access Control (MAC) appear on the CC Exam?

You may be asked to identify the most appropriate access control model for a high-security government agency that requires strict data classification and prevents users from sharing files.

A scenario might describe a system where a user creates a document but is prohibited by the operating system from granting access to a colleague; identify this as MAC.

Expect questions comparing MAC to DAC, where you must select MAC when the primary requirement is to remove the resource owner's ability to manage permissions.

❓ Frequently Asked Questions

How does MAC differ from RBAC in a practical sense?

RBAC assigns permissions based on job functions or roles, whereas MAC assigns them based on security clearances and labels. MAC is generally more restrictive and focused on confidentiality than RBAC.


Why is MAC rarely used in standard corporate environments?

MAC requires significant administrative overhead to maintain labels and clearances for every single user and object, making it too rigid and costly for most commercial business needs.

Related Terms from Certified in Cybersecurity

📝 Related Study Guides

Study Guide 8 min read

ISC2 CC Certification Guide: Your Free Entry into Cyber

The ISC2 Certified in Cybersecurity (CC) is a free, entry-level certification designed for beginners. It covers five core domains—Security Principles, BCP/DR, Access Control, Network Security, and Security Operations—via a 100-question exam. It's the ideal starting point for career changers to build a foundation without financial barriers.

Exam Tips 8 min read

ISC2 CC Exam Domains: What You Need to Know to Pass

The ISC2 CC exam consists of five domains: Security Principles, Business Continuity (BC), Disaster Recovery (DR), and Incident Response (IR), Access Controls, Network Security, and Security Operations. To pass, you must master the CIA Triad and security governance, while prioritizing high-weight domains through targeted practice and domain-specific analytics.

Deep Dive 10 min read

Mastering the CIA Triad for ISC2 CC: A Deep Dive

The CIA triad is the foundational model of information security, consisting of Confidentiality (preventing unauthorized access), Integrity (ensuring data accuracy and consistency), and Availability (guaranteeing reliable access to resources). Balancing these three pillars allows security professionals to manage risk effectively and protect organizational assets against diverse cyber threats.

🧠

Test Your Knowledge

Think you understand Mandatory Access Control (MAC)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium