Information SystemsSecurity- C845 m8 m8
A. ApplyanAccessControlModel 8
m 8
m
A.1. ChosenAccess ControlModel 8
m m8 m
8
Ihave chosen the Role-Based Access Control (RBAC) model. Theprinciples ofRBAC are:
m8 m 8 m 8 m8 m 8 m 8 m 8 m 8 m 8 m8 m8
• Role Assignment: Auser is assigned to a role based on their job function (e.g., ”Finance
m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8
Analyst”).
m8
• PermissionAssignment:Permissionstoperformoperationsonsystemsareassignedtoroles,
8
m 8
m 8
m 8
m 8
m 8
m 8
m
not to individual users.
m8 m8 m8 m8
• SessionManagement: A useractivatesaroletogaintheassociatedpermissionsforasession.
8
m m 8 q 8
m 8
m 8
m 8
m 8
m m
8
• LeastPrivilege: Usersshouldonlyhavetheminimumlevel ofaccessnecessarytoperformtheir job
8
m m8 8
m m
8 8
m m
8 m8 8
m 8
m 8
m m8 m8
duties.
m8
The organization's access control structure, as seen in the user matrix, is implicitly role-based (e.g.,
m 8 m 8 m 8 m 8 m 8 m 8 m 8 m 8 m 8 m8 m 8 m 8 m8 m 8
m”Finance manager,” ”HRcoordinator”). Applying a formal RBACmodel would streamlinethis by ensuring
8 m8 m 8 m 8 m8 m 8 m 8 m 8 m8 m 8 m8
mpermissions arestrictlytiedtobusinessfunctions,reducingcomplexityandthepotentialforusererrorwhen
8 m8 8
m 8
m 8
m 8
m 8
m 8
m 8
m 8
m 8
m 8
m 8
m 8
m 8
m 8
m
assigning permissions.
8
m m8
A.2. FourMisalignments withRBACPrinciples 8
m m8 m
8 8
m
1. Misalignment 1: Privilege Escalation Beyond Role Scope m8 m 8 m8 m8 m 8 m8
• Description: The ”Juniorsystem admin” (J. Lopez) has ”Domain admin” privileges. A m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8
juniorroleshouldnothavethehighestlevelofaccessinaWindowsenvironment.
m8 8
m m
8 m
8 8
m 8
m m
8 m
8 m
8 8
m 8
m m
8 m
8 m
8
• Conflict with RBAC: Thisviolates theprinciple ofleast privilege. The role ”Junior system m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8
admin” implies asubsetofadministrative duties, notunrestricted domain-wide
m8 m 8 m 8 m 8 m 8 m 8
control. m 8
2. Misalignment2: UnnecessaryAccess AcrossDepartments m
8 m 8 m8 m8 m
8
• Description:The”Financeanalyst”(L.Cheng)has”Fullaccess”totheCRM,asystem m
8 m
8 m
8 m
8 m
8 m
8 m
8 m8 m8 m
8 m
8 m8 m
8
primarilyfor Sales and Support. Afinance roletypically does not require full modification
m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8
rights in a customer relationship system. m8 m8 m8 m8 m8 m8
• Conflict with RBAC: This violates least privilege and separation ofduties. It allows for m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8
• potential data manipulation outsidethe user'score business function.
m8 m8 m8 m
8 m8 m
8 m8 m8
?
,3. Misalignment3: Violation ofUser-RoleAssignment Post-Termination
8
m m8 m8 8
m 8
m m8
• Description: The"HRassistant" (P. Ellis), who was terminatedon2025-05-20, has an
8
m m
8 m
8 8
m m
8 m
8 8
m m
8
"Active" account status and successfully logged in on 2025-06-29.
m8 m8 m8 m8 m8 m8 m8 m8 m8
• Conflictwith RBAC: RBAC requires timely revocationof role assignments upon a change in
m
8 m8 m8 m8 m8 m
8 m8 m
8 m8 m8 m 8
employment status. An active session for a terminated user completely bypasses the
m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8
security provided by the role structure.
m8 m8 m8 m8 m8 m8
4. Misalignment4: OverlyBroad Privileged Access
8
m m8 8
m m8 m8
• Description: The "IT administrator" (T. Miller) has "Full admin" access to "All internal
8
m m
8 8
m m8 m8 m8 8
m m8 m8 m
8 m
8 m8
systems," and the log shows they made a firewall rule change without a ticket_id.
m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8 m8
• ConflictwithRBAC:Whilesomeaccessisnecessary, blanket"Full admin" access
8
m 8
m 8
m m8 8
m m 8 m8
?
, vioIatesIeastpriviIegeandimpedesaccountabiIity. Itdoesnotsegmentdutieswithinthe IT department
8
m 8
m 8
m 8
m 8
m m8 8
m 8
m 8
m 8
m 8
m m8 m8
itseIf.
m8
?