Access Control Matrix: Model & Example

An error occurred trying to load this video.

Try refreshing the page, or contact customer support.

Coming up next: What is Encryption? - Definition, Types & Methods

You're on a roll. Keep up the good work!

Take Quiz Watch Next Lesson
 Replay
Your next lesson will play in 10 seconds
  • 0:03 When To Use an Access…
  • 1:05 What Is An Access…
  • 2:31 Access Control Matrix…
  • 2:54 Access Control Models
  • 4:25 Lesson Summary
Save Save Save

Want to watch this again later?

Log in or sign up to add this lesson to a Custom Course.

Log in or Sign up

Timeline
Autoplay
Autoplay
Speed Speed

Recommended Lessons and Courses for You

Lesson Transcript
Instructor: Kent Beckert

Kent is an adjunct faculty member for the College of Business at Embry-Riddle Aeronautical University and has a Master's degree in Technical Management.

An access control matrix is a single digital file assigning users and files different levels of security. We'll talk about access control models including: mandatory access, role-based access, discretionary access, and rule-based access.

When to Use an Access Control Matrix

You have made an appointment with a human resource (HR) representative to discuss several team members being considered for a promotion. During the meeting, sensitive personal and confidential information was shared. Showing some concern, the HR manager ensured everyone that the information will be protected and remain secure.

A digital record was prepared documenting each discussion point, including accomplishments, the applicable dates, times, locations, and the identity of the individuals responsible. Additionally, historical records of previous performances by the same individuals were shared with the attending members.

In this example, everyone has the right to expect confidentiality and be assured the information will be safeguarded except to those that need to know. Therefore, it becomes the primary responsibility of the HR manager to ensure the integrity of all associated records. To accomplish this, the HR manager has in place a reliable set of access control security guidelines.

What Is an Access Control Matrix?

Access to any type of information is regulated by organizations having either physical or logical access controls in place, some organizations offering both.

  • Physical controls are present to prevent a person from entering office spaces, buildings, or structures.
  • Logical controls are designed to limit electronic access to a network, a computer, digital files, and stored data.

For the purpose of this lesson, let's focus on the logical access controls, one of which is an access control matrix.

An access control matrix is a single digital file or written record having 'subjects' and 'objects' and identifies what actions, if any, are permitted by individuals. In simple terms, the matrix allows only certain people (subjects) to access certain information (objects).

As shown in this table, the matrix consists of one or more subjects (or people) along one axis and the associated objects (or files) along the other axis. Certain people are allowed to read (R), write (W), execute (E), and delete (D) files. Restricted access is indicated by a dash.

HR Records Gary Sandy Tonya Robyn Samantha
Salary Files RWED R - ED - - - - RWED RWED
Promotion List - - - D R - E - RWED RWED - - - -
Performance Reports RWED RW - D - - - - - - - - RWE -

For example, you can see that Gary is allowed to delete the promotion list, whereas Sandy is allowed to read or execute it. Tonya has full access, while Samantha has no access whatsoever.

Access Control Matrix Explained

When setting up access controls, the systems administrator must adhere to three primary principles:

To unlock this lesson you must be a Study.com Member.
Create your account

Register to view this lesson

Are you a student or a teacher?

Unlock Your Education

See for yourself why 30 million people use Study.com

Become a Study.com member and start learning now.
Become a Member  Back
What teachers are saying about Study.com
Try it risk-free for 30 days

Earning College Credit

Did you know… We have over 200 college courses that prepare you to earn credit by exam that is accepted by over 1,500 colleges and universities. You can test out of the first two years of college and save thousands off your degree. Anyone can earn credit-by-exam regardless of age or education level.

To learn more, visit our Earning Credit Page

Transferring credit to the school of your choice

Not sure what college you want to attend yet? Study.com has thousands of articles about every imaginable degree, area of study and career path that can help you find the school that's right for you.

Create an account to start this course today
Try it risk-free for 30 days!
Create an account
Support