Module 6 Overview
February 15-21 · Presidents' Day is Monday, February 15 · Reading: 13 pages · Estimated total: 6.5 hours
Last week the system worked out who you are. This week it decides what you may do about it.
The core idea is old and simple: write down, for every subject and every object, what that subject may do to that object. That is an access control matrix, and it is the most direct way to express a policy. Almost no system stores it that way, and the reasons why produce the two shapes real systems actually use (access control lists and capability lists), plus the shape most enterprises have settled on, role-based access control.
The week ends with the part people skip: accountability. Knowing what somebody was allowed to do is not the same as knowing what they did.
Learning Objectives
By the end of this week, the successful student will be able to:
- 2.4: Construct an access control matrix for a given set of subjects, objects, and permissions.
- 2.5: Express an access control policy as an ACL, a capability list, and an RBAC assignment, and state the tradeoffs among them.
- 5.3: Apply least privilege and separation of privilege to reduce an over-broad permission assignment.
Assignments and Tasks
Due by Sunday at 11:59 p.m. Mountain Time
- Read 6.01 Readings and Lecture Notes and work the worked example (2 hrs 25 min)
- 6.02 Lab 3: Access Control Matrix and Least Privilege (1 hr 30 min, 38 points)
No discussion this week. Presidents' Day is Monday, so the working week is short.
Time Estimate
| Activity | Time |
|---|---|
| Reading (13 pages) | 1 hr 45 min |
| The notes page and the worked example | 40 min |
| Lab 3 | 1 hr 30 min |
| Review and slack | 2 hrs 30 min |
| Total | ~6.5 hrs |