A library catalog system holds only public bibliographic data and needs simple staff roles, while a police evidence vault needs label-enforced separation. What should the CISO emphasize when choosing authorization models?
Select an answer to reveal the explanation.
Short Explanation
Not every filing room needs a SCIF stamp. Public catalog? Simple roles are fine. Evidence vault? Bring the labels. Pick the model that fits the data and how people actually work—do not MAC the whole city for sport.
Full Explanation
Authorization mechanism selection is risk-driven: MAC suits highly sensitive, centrally labeled data; RBAC or lighter models often suffice for low-sensitivity collaborative systems. Forcing MAC onto a public library catalog adds operational friction without proportional risk reduction, while DAC on an evidence vault invites uncontrolled sharing. CISSP practice is to align the model with sensitivity, threat, and ops capacity.