Skip to main content

Access Control Models - RBAC, ABAC, and ACL

About 2 min read

Access control is a mechanism for managing the scope within which users and systems can access resources (files, databases, network devices, and so on). It consists of two stages, "authentication" (verifying who you are) and "authorization" (determining what you can do), and is a concept that forms the foundation of zero trust security. As of 2025, the adoption of ABAC and PBAC (policy-based access control) is advancing, and dynamic, context-aware access decisions are becoming mainstream.

Separating Permissions by Environment

A common approach when designing access control in cloud environments is to assign the same person different permissions in different environments. A typical arrangement gives the development team free rein in the staging environment, limits them to read-only in production, and allows changes to production only through one fixed route: the CI/CD pipeline. Because the permissions needed for daily work are preserved while the path for manual operations to reach production directly is closed, there is less room for a mistaken action to turn straight into a production incident.

Comparison of Access Control Models

ModelControl methodFlexibilityMain use
DAC (discretionary)Set by the ownerHighFile systems
MAC (mandatory)Label-basedLowMilitary and government agencies
RBAC (role)Tied to rolesMediumEnterprise IT systems
ABAC (attribute)Combination of attributesHighestCloud and zero trust

Major Access Control Models

DAC (discretionary access control) is a model in which the resource owner sets the permissions, with file system read and write permissions being a typical example. MAC (mandatory access control) is a model in which the system controls access based on security labels, and it is adopted by military and government agencies. RBAC (role-based access control) is a model that ties permissions to a user's role, and it is the most widely used in enterprise IT systems. ABAC (attribute-based access control) is the latest model, which makes decisions dynamically by combining attributes such as time of day, location, and device.

Design Scenarios in Practice

For example, on an e-commerce site, a basic RBAC design is one in which general users can view only their own order history, customer support can only view customer information, and administrators can read and write all data. Following the principle of least privilege, you grant each role only the minimum necessary permissions. In cloud environments, IAM (Identity and Access Management) policies allow fine-grained control, letting you enforce rules such as "developers cannot write to the production database." Data breaches caused by misconfigured access controls on cloud storage occur frequently, so regular permission reviews are essential.

Operational Tips

Access control is not "set it and forget it"; periodic auditing is important. Failing to delete the accounts of departed employees and leaving unnecessary permissions in place after a transfer can become a foothold for privilege escalation attacks. Combine a sufficiently long random password with multi-factor authentication to strengthen authentication.

Related Terms

Was this article helpful?