非自主访问控制与RBAC的区别:不同资料表述矛盾解析
Great question—this is a super common point of confusion because terminology can get messy across different cybersecurity resources. Let’s break this down clearly to resolve the ambiguity:
Core Conclusion
Non-discretionary Access Control (NDAC) is a broad category of access control models, while Role-Based Access Control (RBAC) is a specific implementation that falls under the NDAC umbrella. They are not the same concept, though some resources (like Cisco materials) use shorthand that blurs this line by referring to RBAC as NDAC (since RBAC is the most widely used NDAC model today).
Key Differences Between NDAC and RBAC
1. Scope & Classification
- NDAC: This is a high-level classification where access decisions are controlled by a central authority (e.g., a security admin), not the resource owner (unlike Discretionary Access Control, DAC). It’s an umbrella term that includes multiple distinct models, not just RBAC.
- RBAC: A specific sub-model of NDAC that organizes access around predefined roles (e.g., "HR Specialist", "DevOps Engineer"). Permissions are assigned to roles, and users are assigned to roles—streamlining access management at scale.
2. Flexibility & Use Cases
- NDAC models vary widely in rigidity: For example, Mandatory Access Control (MAC) (another NDAC model) uses strict, unchangeable labels (like "Top Secret" or "Public") and clearance levels. It’s designed for highly regulated environments (e.g., government, defense) where access rules can’t be modified by users.
- RBAC is inherently flexible: Roles can be created, updated, or retired as organizational needs shift. You can also add role hierarchies (e.g., "Senior Developer" inherits permissions from "Junior Developer") and separation of duties (e.g., a user can’t approve their own expense reports) to enforce security policies.
3. Basis for Access Decisions
- NDAC in general: Access rules can be based on any centrally defined attribute—user clearance, job function, time of day, location, or even specific rules (like "allow access only during business hours").
- RBAC specifically: Access is tied directly to job roles. Permissions are grouped into roles that align with what a user needs to do their job, rather than assigning permissions to individual users one by one.
Why CISSP Separates Them vs. Other Resources
- CISSP follows a formal, taxonomy-focused approach to cybersecurity concepts. It explicitly splits NDAC into its sub-models (MAC, RBAC, Rule-Based Access Control (RuBAC)) to ensure clarity for professionals who need to understand the full spectrum of access control options.
- Other resources (like Cisco materials) often simplify terminology for practical, real-world contexts. Since RBAC is the most commonly deployed NDAC model in corporate environments, they might use "NDAC" as a shorthand for RBAC. While this is understandable in a training context, it’s technically imprecise.
Quick Recap
- NDAC = umbrella category of centrally controlled access models
- RBAC = one specific, flexible model within NDAC (alongside MAC, RuBAC, etc.)
内容的提问来源于stack exchange,提问作者arif
相关产品推荐
相关产品推荐

