Access control is the security discipline that governs who or what is permitted to view, use, or modify resources within a system or application.
Access control is the mechanism that enforces policies determining which users or systems can access specific resources and what actions they may perform. It encompasses authentication, authorization, and accountability. Properly implemented access control prevents unauthorized data access and is foundational to every security architecture.
Role-Based Access Control assigns permissions based on predefined roles such as admin or user. Attribute-Based Access Control evaluates multiple attributes like user department, time of day, and resource sensitivity to make dynamic authorization decisions. ABAC offers finer granularity but adds complexity to policy management.
Broken access control ranks as the number one OWASP Top 10 risk because it is pervasive and directly leads to unauthorized data access. Developers frequently rely on client-side enforcement or fail to validate permissions server-side. Manual penetration testing is essential because automated scanners struggle to understand authorization context.
The principle of least privilege dictates that users and processes should only receive the minimum permissions necessary to perform their tasks. This limits the blast radius if an account is compromised. Implementing least privilege requires regular access reviews and removing standing privileges that are no longer needed.
ioSENTRIX testers manually enumerate roles, privileges, and access boundaries within the application. We test horizontal and vertical privilege escalation, insecure direct object references, and missing function-level access controls. Our CREST-accredited methodology goes beyond automated scanning to uncover logic-based authorization bypasses.
Horizontal privilege escalation occurs when a user accesses another user's resources at the same privilege level. Vertical privilege escalation involves a lower-privileged user gaining higher-privileged access such as admin functionality. Both types result from insufficient server-side authorization checks on sensitive operations.
Implement access control server-side with deny-by-default policies. Use framework-level authorization middleware, validate permissions on every request, and log all access decisions. Avoid relying on hidden UI elements for security. Regular penetration testing validates that access controls function correctly under adversarial conditions.
Mandatory Access Control is a strict model where the operating system enforces access policies based on security labels assigned to subjects and objects. Users cannot override these policies. MAC is commonly used in military and government systems where data classification levels such as Secret and Top Secret require rigid separation.