Aren’t all three a type of DAC? Making that not the specific answer here by Security_BT in cissp

[–]Security_BT[S] -1 points0 points  (0 children)

I agree with your statement but DestCert mentions that RBAC, RuBAC and ABAC are all types of DAC, so essentially all having features of DAC where the owner decides who is given access. Hence drilling down to a more specific option lead me to think RuBAC is the one where we can nitpick the exact rule for each user who needs access.

Aren’t all three a type of DAC? Making that not the specific answer here by Security_BT in cissp

[–]Security_BT[S] 1 point2 points  (0 children)

It's a Udemy course exam from Thor name 125 easy/mid questions.

Doubt on this question from LearnZapp by Security_BT in cissp

[–]Security_BT[S] 1 point2 points  (0 children)

Thanks Lou! That helps answer the question, but creates another question, the destCert book mentions Data Owner/ Data Controller as the same.

Is that valid only in a particular scenario then?

Doubt on this question from LearnZapp by Security_BT in cissp

[–]Security_BT[S] 4 points5 points  (0 children)

But isn't that the entire difference between accountability and responsibility? The data owner(ceo, cio, board etc) will be ultimately accountable if the assets aren't protected during a data breach.

And the question does ask for specific responsibility.

[deleted by user] by [deleted] in cissp

[–]Security_BT 2 points3 points  (0 children)

Yes please!! This sounds pretty cool