Skip to main content

Unit 5 · Topic 5.2

5.2 Protecting Applications and Data: Managerial Controls and Access Controls

Not all data needs the same protection, and not everyone should be able to touch it. This topic covers data states and regulated data types, the policies that govern encryption and web apps, the four access control models plus least privilege, and how to read and set Linux file permissions with ls -l and chmod.

Key terms

  • data at rest, in transit, in use
  • PII, PHI and PCI
  • role-based access control (RBAC)
  • mandatory access control (MAC)
  • least privilege
  • chmod

Data states and regulated data

Data at rest is stored on a drive: protect the drive from theft or destruction, and encrypt the data. Data in transit is moving between devices: protect the cables or other media, and encrypt the data. Data in use is being worked on by software or a person: it must be decrypted to be used, so access controls decide who can view or edit it.

Organizations rank data by sensitivity and protect the most sensitive data most. Laws and industry rules also require some data to be stored, sent and handled in specific ways, so organizations label regulated data and write policies to comply:

  • Personally identifiable information (PII) identifies a person: name, signature, phone number, address, biometrics, Social Security number, birthdate, email. Laws include the Privacy Act of 1974 (records held by federal agencies) and, for children under 13, the Children's Online Privacy Protection Act (COPPA) of 1998.
  • Protected health information (PHI) covers health, treatment and payment for care: test results, treatment and hospital records, doctor's notes, billing records. It's protected under HIPAA (the Health Insurance Portability and Accountability Act of 1996).
  • Payment card information (PCI) is what's needed to process card payments: name, account number, expiration date, address and CVV code. It's governed by the Payment Card Industry Data Security Standard (PCI DSS), an industry standard rather than a law.

Policies for data and applications

A cryptography policy lists approved encryption algorithms for each use, minimum or maximum key lengths, and rules for generating and storing keys. A web application security policy says when an app must get a security assessment, how fast flaws must be fixed based on risk, and how assessments are done (which tools or frameworks).

Access control models

Access control decides which subjects (users or programs) can perform which operations (read, change, add, remove) on which objects (files or programs).

  • Role-based (RBAC): each subject gets a role, and roles get access. Only people in the role "nurse" can open the medication app.
  • Rule-based (RuBAC): access is checked against rules, like time of day or network location, usually layered on top of another model. No one can open the grading system after 10 p.m., even teachers.
  • Discretionary (DAC): owners decide who can access what they own, and administrators can override. You share your document with one friend as editor and another as viewer.
  • Mandatory (MAC): an outside administrator assigns levels to every subject and object, and strict rules govern access across levels. The Bell-LaPadula model, used by governments and militaries, says you may not read above your level and may not write below it: "write up, read down."
  • Least privilege: give every user and program exactly the access its job needs, and no more.

Linux permissions

Authorization means granting someone a certain type of access to a resource. Linux sets three permissions, always in this order: read (r), write (w) and execute (x, run a program). A dash means the permission is missing, so r-x is read and execute without write. They're set for three entities, always in this order: the owner, the group, and others. So rwxr-x--- means owner rwx, group r-x, others nothing. (On a directory, x lets you enter it and reach the files inside, and r lets you list what's in it.)

ls -l shows a file's permissions, like -rw-r----- 1 kpark science 2048 Mar 2 10:15 grades.csv. The first character is - for a file or d for a directory, then the nine permission characters, then the owner (kpark) and group (science). A + after the permissions means extra permissions are set; view them with getfacl.

chmod changes permissions. Numeric method: one digit per entity (owner, group, others), adding read 4, write 2 and execute 1. chmod 750 report gives rwx (4+2+1), r-x (4+1) and nothing (0). Symbolic method: who (u owner, g group, o others, a all), then + to add or - (a hyphen) to remove, then r, w or x. chmod g+w report adds write for the group; chmod ug+rx report adds read and execute for owner and group; chmod o-r report removes read from others.

DigitPermissions
7rwx
6rw-
5r-x
4r--
3-wx
2-w-
1--x
0---

Worked examples

Try each one yourself first, then open the solution.

  1. Example 1

    From requirement to chmod

    The file budget.xlsx must let its owner read and write it, let members of its group only read it, and give everyone else no access. Write the numeric chmod command and the permission string ls -l would then show.

    Show the solution
    1. Step 1: Owner: read + write = 4 + 2 = 6.
    2. Step 2: Group: read only = 4.
    3. Step 3: Others: nothing = 0.
    4. Step 4: Put the digits in order (owner, group, others): 640.
    5. Step 5: Write each as letters: 6 = rw-, 4 = r--, 0 = ---, so the string is rw-r----- after the leading - for a file.

    Answer: chmod 640 budget.xlsx, shown by ls -l as -rw-r-----.

  2. Example 2

    Reading and fixing permissions

    ls -l shows: -rwxrw-rw- 1 dlee staff 512 Apr 9 08:30 backup.sh. Others should have no access, and the group should be able to read and run the script but not change it. Give the current numeric value, the target value, and symbolic commands that make the change.

    Show the solution
    1. Step 1: Split the nine characters into threes: rwx | rw- | rw-.
    2. Step 2: Convert: rwx = 7, rw- = 6, rw- = 6, so it's currently 766.
    3. Step 3: Target: owner unchanged (rwx = 7); group read + execute (r-x = 5); others nothing (0). Target is 750.
    4. Step 4: Symbolic fix: the group needs w removed and x added, and others need r and w removed: chmod g-w backup.sh, chmod g+x backup.sh, chmod o-rw backup.sh. (Or simply chmod 750 backup.sh.)

    Answer: Current 766, target 750. Symbolic: chmod g-w backup.sh, chmod g+x backup.sh, chmod o-rw backup.sh (or chmod 750 backup.sh).

  3. Example 3

    Choosing an access control model

    Pick the best model for each: (a) A bank wants tellers, loan officers and managers to have different access, assigned by job; (b) a defense agency labels documents Confidential, Secret and Top Secret and clears staff to matching levels; (c) a company wants payroll locked except from the office network during business hours.

    Show the solution
    1. Step 1: (a) Access depends on job title: role-based (RBAC).
    2. Step 2: (b) An outside authority assigns levels to people and documents, with strict cross-level rules: mandatory (MAC), such as Bell-LaPadula.
    3. Step 3: (c) Access depends on conditions (time and location): rule-based (RuBAC), layered on whatever model already decides who may use payroll.

    Answer: (a) RBAC. (b) MAC (Bell-LaPadula). (c) RuBAC.

Common mistakes

  • Getting the chmod digit order wrong. It's always owner, group, others, and r = 4, w = 2, x = 1.
  • Reversing Bell-LaPadula. It's "write up, read down": no reading above your level, no writing below it.
  • Confusing role-based and rule-based. Roles are about who you are (your job); rules are about conditions like time or location.
  • Calling PCI DSS a law. It's an industry standard; HIPAA, COPPA and the Privacy Act are laws.

On the exam

  • Expect chmod in both directions: turning a requirement or an ls -l string into a command, and explaining what a given command does to each entity. Check your digits by converting back to letters.
  • Access-model questions describe a need; match key words: job or position (RBAC), time or place conditions (RuBAC), owner shares (DAC), clearance levels (MAC).

Connected topics

Videos

  • Access Controls - CompTIA Security+ SY0-701 - 4.6

    Professor MesserWatch on YouTube (opens in a new tab)

  • Linux File Permissions in 5 Minutes | MUST Know!

    Travis MediaWatch on YouTube (opens in a new tab)

  • States of Data - CompTIA Security+ SY0-701 - 3.3

    Professor MesserWatch on YouTube (opens in a new tab)

  • Linux Commands for Beginners 21 - Changing Permissions Numerically

    Learn Linux TVWatch on YouTube (opens in a new tab)

  • CertMike Explains The Bell LaPadula Model

    Mike ChappleWatch on YouTube (opens in a new tab)

  • Personally Identifiable Information (PII) | Internet safety | Khan Academy

    Khan AcademyWatch on YouTube (opens in a new tab)

Check yourself: 5.2 Protecting Applications and Data: Managerial Controls and Access Controls

5 questions on 5.2 Protecting Applications and Data: Managerial Controls and Access Controls. Pick an answer to see if you got it, and why.

Item 1: Patient files saved on a clinic's file server.

Item 2: Lab results being sent over the internet from a lab to the clinic.

Item 3: A patient's chart open on a doctor's screen while the doctor edits it.

Invented scenario

Question 1 of 5

Which list correctly gives the state of the data in Items 1, 2 and 3?

Question 2 of 5

Why can't encryption alone protect the data in Item 3?

Record 1: A patient's name and blood test results.

Record 2: A customer's card number, expiration date and CVV code.

Record 3: An employee's name, home address and Social Security number.

Invented records

Question 3 of 5

Which pair correctly classifies Records 1 and 2?

Question 4 of 5

Which law or standard most directly governs the protection of Record 1?

Question 5 of 5

How should an organization that collects Record 3 handle it?

0 of 5 answered