ISC Exam Questions

Access control that is a function of factors such as location, time of day, and previous access hist

Access control that is a function of factors such as location, time of day, and previous access history
is called:

A.
Information flow

B.
Context-dependent

C.
Positive

D.
Content-dependent

Explanation:
In answer “Context-dependent”, access is determined by the context of the decision as opposed to
the information contained in the item being accessed. The latter is referred to as content-dependent
access control. In contentdependent access control, for example, the manager of a department may
be authorized to access employment records of a department employee, but may not be permitted
to view the health records of the employee. * The term positive in access control refers to positive
access rights, such as read or write. Denial rights, such as denial to write to a file, can also be
conferred upon a subject. * Information flowdescribes a class of access control models. An
information flow model is described by the set consisting of object, flow policy, states, and rules
describing the transitions among states.