Discretionary Access Control
- (DAC) A means of restricting access to objects based on the identity of subjects and/or groups to which they belong. (NSTISSI 4009) NOTE: Controls are discretionary in the sense that a subject with a certain access permission is capable of passing that permission (directly or indirectly) to any other subject. The controls are discretionary in the sense that a subject with a certain access permission is capable of passing that permission (perhaps indirectly) on to any other subject (unless restrained by mandatory access control). (DODD 5200. 28-STD;)
- A means of restricting access to objects based on the identity and need-to-know of subjects and/or groups to which they belong. The controls are discretionary in the sense that a subject with a certain access permission is capable of passing that permission (perhaps indirectly) on to any other subject. Compare MANDATORY ACCESS CONTROL. (NCSC-WA-001-85;; CSC-STD-001-83;; CSC-STD-004-85;)