Skip to content

Module 6 Overview ​

February 15-21 · Presidents' Day is Monday, February 15 · Reading: 13 pages · Estimated total: 6.5 hours

Last week the system worked out who you are. This week it decides what you may do about it.

The core idea is old and simple: write down, for every subject and every object, what that subject may do to that object. That is an access control matrix, and it is the most direct way to express a policy. Almost no system stores it that way, and the reasons why produce the two shapes real systems actually use (access control lists and capability lists), plus the shape most enterprises have settled on, role-based access control.

The week ends with the part people skip: accountability. Knowing what somebody was allowed to do is not the same as knowing what they did.

Learning Objectives ​

By the end of this week, the successful student will be able to:

  • 2.4: Construct an access control matrix for a given set of subjects, objects, and permissions.
  • 2.5: Express an access control policy as an ACL, a capability list, and an RBAC assignment, and state the tradeoffs among them.
  • 5.3: Apply least privilege and separation of privilege to reduce an over-broad permission assignment.

Assignments and Tasks ​

Due by Sunday at 11:59 p.m. Mountain Time ​

No discussion this week. Presidents' Day is Monday, so the working week is short.

Time Estimate ​

ActivityTime
Reading (13 pages)1 hr 45 min
The notes page and the worked example40 min
Lab 31 hr 30 min
Review and slack2 hrs 30 min
Total~6.5 hrs

Released under the MIT License.