Protecting Applications and Data: Managerial Controls and Access Controls · 保护应用程序和数据:管理控制和访问控制
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| at rest/æt rest/ | 静态数据 | jìng tài shù jù |
| in transit/ɪn ˈtrænsɪt/ | 传输中数据 | chuán shū zhōng shù jù |
| in use/ɪn juːs/ | 使用中数据 | shǐ yòng zhōng shù jù |
| PII/ˌpiː aɪ ˈaɪ/ | 个人身份信息 | gè rén shēn fèn xìn xī |
| PHI/ˌpiː eɪtʃ ˈaɪ/ | 受保护健康信息 | shòu bǎo hù jiàn kāng xìn xī |
| PCI/ˌpiː siː ˈaɪ/ | 支付卡信息 | zhī fù kǎ xìn xī |
| RBAC/ˈɑːbæk/ | 基于角色的访问控制 | jī yú jué sè de fǎng wèn kòng zhì |
| RuBAC/ruː bæk/ | 基于规则的访问控制 | jī yú guī zé de fǎng wèn kòng zhì |
| DAC/ˌdiː eɪ ˈsiː/ | 自主访问控制 | zì zhǔ fǎng wèn kòng zhì |
| MAC/mæk/ | 强制访问控制 | qiáng zhì fǎng wèn kòng zhì |
| principle of least privilege/ˈprɪnsɪpl ɒv liːst ˈprɪvɪlɪdʒ/ | 最小权限原则 | zuì xiǎo quán xiàn yuán zé |
Data states and laws
- Data can be at rest 静态数据, in transit 传输中数据, or in use 使用中数据.
- Laws protect PII 个人身份信息, PHI 受保护健康信息, and PCI 支付卡信息.
- Sensitive data earns stronger controls.
数据状态与法律
- 数据可以是静态数据(at rest)、传输中数据(in transit)或使用中数据(in use)。
- 法律保护PII(个人身份信息)、PHI(受保护健康信息)和PCI(支付卡信息)。
- 敏感数据获得更强的控制。
Four access-control models
- RBAC 基于角色的访问控制: access follows your role.
- RuBAC 基于规则的访问控制: access follows a condition (like time).
- DAC 自主访问控制: the owner decides. MAC 强制访问控制: a central admin sets levels.
四种访问控制模型
- RBAC(基于角色的访问控制):访问跟随你的角色。
- RuBAC(基于规则的访问控制):访问跟随一个条件(如时间)。
- DAC(自主访问控制):所有者决定。MAC(强制访问控制):中央管理员设定级别。
Which access-control model fits the rule? · 哪种访问控制模型符合该规则?
RBAC follows your role; RuBAC follows a condition; DAC lets the owner decide; MAC uses central levels. · RBAC遵循你的角色;RuBAC遵循条件;DAC由所有者决定;MAC使用中心级别。
"Allow access only during business hours" describes which model? · “仅允许在工作时间访问”描述的是哪种模型?
A condition (time) = RuBAC. · 一个条件(时间)= RuBAC。
In ____ access control, the owner of a file decides who else may use it. · 在 ____ 访问控制中,文件所有者决定谁可以使用它。
DAC = the owner decides. · DAC = 所有者决定。
Linux permissions
- Each file has read (4), write (2), execute (1) for owner, group, others.
chmod 640= owner read+write (6), group read (4), others none (0).- The principle of least privilege 最小权限原则 guides every model.
Linux权限
- 每个文件对所有者、组、其他人有读(4)、写(2)、执行(1)。
chmod 640= 所有者读+写(6)、组读(4)、其他人无(0)。- 最小权限原则(principle of least privilege)指导每个模型。
Tell the four access models apart by their decider, not their name. RBAC = your role, RuBAC = a condition, DAC = the file's owner, MAC = a central admin. Exam questions describe the rule and ask you to name the model.
通过它们的决定者而非名称来区分四种访问模型。RBAC=你的角色,RuBAC=一个条件,DAC=文件的所有者,MAC=中央管理员。考试题目描述规则并要求你命名模型。
What single number sets owner read+write, group read, others none? (chmod ___) · 哪个单一数字设置所有者读写、组只读、其他人无权限?(chmod ___)
6 (4+2), 4, 0 → 640.
The principle of least privilege gives each entity exactly the access it needs, no more. · 最小权限原则赋予每个实体恰好所需的访问权限,不多不少。
Least privilege · 最小权限 limits access to what is needed. · 最小权限 将访问限制在所需范围内。
Match each access model to its decider. · 将每种访问模型与其决策者匹配。
Each model has a different decider. · 每个模型有不同的决策者。
To set report.txt so the owner can read and write, the group can only read, and others get nothing: read+write = 4+2 = 6, read = 4, none = 0. The command is chmod 640 report.txt.
要设置 report.txt 让所有者能读写、组只能读、其他人什么都没有:读+写=4+2=6,读=4,无=0。命令是 chmod 640 report.txt。
Data is protected by its state and by law (PII/PHI/PCI). Access control uses four models — RBAC (role), RuBAC (condition), DAC (owner), MAC (admin levels) — all guided by least privilege. On Linux, permissions add read 4 + write 2 + execute 1 per group.
数据受其状态和法律(PII/PHI/PCI)保护。访问控制使用四种模型——RBAC(角色)、RuBAC(条件)、DAC(所有者)、MAC(管理员级别)——全都以最小权限为指导。在Linux上,权限对每个组累加读4+写2+执行1。