You are on page 1of 2

Information Security

CSC432
BCT SP23
Assignment No. 2

Q1. Consider the example of COMSATS University Islamabad which is comprised of different subjects
(such as students, teachers, faculty members, administration and visiting guests. There are
numerous resources in this network such as library, student café, server room, computer labs,
and student affairs etc. There are different types of data stored at different locations about
different resources such as students marks at Exam Server, student attendance at CU Online
server, digital books in the library server etc. Often, some guests visit the university and bring in
important files or they are handed over some important information.

Figure 1: An example of university network with subjects coming in and going out and interacting with
different objects

Considering the above scenario, you need to draw an access control for COMSATS University. You
need to give examples of following access control discussed in the class and relate your example in
COMSATS University scenario.

1. Discretionary Access Control


2. Non-discretionary Access Control
3. Mandatory Access Control
4. Content based Access Control
5. Role Based Access Control
6. Rule Based Access Control
7. Risk Based (Adaptive) Access Control
How to solve:

Your answer/example must be related to the information security and not to the tangible objects.
Though, describing the access control on tangible objects is part of access control but in this
assignment, you are required to provide the access control example on the different types of data
only.

Your answer/example about each subject accessing an object must not be more than few lines.

Not all the details are provided in the above scenario. If you find some details as missing, you can
assume and add your explanation.

There is no need to add assignment cover page (think green). You can type write your name and
registration number on top of the page.

Use Times New Roman font 12 for your text. For heading/sub-headings use times new roman
12 bold.

Submission Deadline: Softcopy PDF only on MS teams before 11.59pm on Thursday 13 th April 2023
Hardcopy: Through CR before 11.30am on Friday 14-04-2023

NOTE: A missed/late submission will not be retaken or reconsidered. Better to submit well before
the deadline expires to avoid power failure or network connectivity issues.

You might also like