An IS auditor reviewing a financial system finds that users can access any record regardless of their department. Which access control model is MOST appropriate to remediate this?
-
A
Mandatory Access Control (MAC)
-
B
Discretionary Access Control (DAC)
-
C
Role-Based Access Control (RBAC)
-
D
Rule-Based Access Control