ISC Exam Questions

what privilege they have?

With Discretionary access controls, who determines who has access and what privilege they
have?

A.
End users.

B.
None of the choices.

C.
Resource owners.

D.
Only the administrators.

Explanation:
Discretionary access controls can extend beyond limiting which subjects can gain what
type of access to which objects. Administrators can limit access to certain times of
day or days of the week. Typically, the period during which access would be permitted
is 9 a.m. to 5 p.m. Monday through Friday. Such a limitation is designed to ensure that
access takes place only when supervisory personnel are present, to discourage
unauthorized use of data. Further, subjects’ rights to access might be suspended when
they are on vacation or leave of absence. When subjects leave an organization
altogether, their rights must be terminated rather than merely suspended. Under this
type of control, the owner determines who has access and what privilege they have.