iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Mandatory access control (MAC) is an access-control policy in which a central authority, not the owner of a resource, decides who may access it and what they may do with it. A user who has been granted access cannot simply pass that access on, grant privileges to others, change security attributes, or alter the rules that govern the system.
What the term means
NIST’s Computer Security Resource Center (CSRC) glossary defines MAC as a nondiscretionary access-control policy. The entry attributes the core wording to CNSSI 4009-2022: access control policy decisions are made by a central authority, not by the individual owner of an object. In a label-based formulation, access depends on the sensitivity label attached to an information resource and on the user’s formal authorization to access information at that sensitivity level. NIST CSRC: mandatory access control (MAC) glossary
What a MAC policy restricts
The most useful way to understand MAC is by looking at what an authorized user is prevented from doing. The NIST SP 800-53 Rev. 5 wording reproduced in the same glossary entry describes constraints on:
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →- passing information on to other subjects;
- granting privileges to others;
- changing the security attributes of subjects or objects;
- choosing the security attributes assigned to new or modified objects;
- changing the access-control rules themselves.
The same wording notes that designated trusted subjects may be given defined privileges for these actions. So MAC does not forbid all delegation; it places those powers under the central policy and limits them to explicitly trusted roles.
#1 Best Overall
MAC compared with discretionary access control
MAC is usually explained by contrast with discretionary access control (DAC). NIST’s DAC glossary describes a model in which the object owner, or another authorized party, can decide who receives access rights and what those rights should be. MAC restricts exactly that capability, so the owner’s choices are bounded by the central policy.
| Question | Mandatory access control (MAC) | Discretionary access control (DAC) |
|---|---|---|
| Who sets access decisions? | A central authority | The object owner or another authorized party |
| Can an authorized user pass access on? | Restricted by policy | Owner discretion is allowed |
| Who can change security attributes or labels? | Limited to the central policy and designated trusted subjects | Not governed by a central label policy in the same way |
| What typically drives the decision? | Sensitivity labels and formal authorization | Ownership and the owner’s grants |
The table describes the models at the level of policy authority. It does not mean that a particular operating system or product implements one model and nothing else.
How MAC differs from attribute-based access control
Attribute-based access control (ABAC) is often discussed alongside MAC. NIST SP 800-162 describes ABAC as evaluating attributes of the subject, the object, the requested operation, and sometimes environmental conditions against a policy, set of rules, or relationships. That makes ABAC a flexible framework built on attributes, while MAC is defined by who controls the policy and which decisions users may make.
The NIST material does not establish that MAC and ABAC are mutually exclusive. A system can use central, nondiscretionary control over certain decisions while also evaluating attributes when making them. The distinction is one of emphasis rather than a strict either-or classification.
A worked illustration
NIST’s glossary uses a military-security example: an individual data owner does not decide who holds a top-secret clearance, and cannot change an object’s classification from top-secret to secret. The example shows central authority over clearance and classification. It is an illustration, not a statement that every MAC deployment is a military system.
Source notes for citing this definition
- The NIST CSRC MAC glossary lists CNSSI 4009-2022 and several NIST publications as sources. Its entry combines wording from different sources, so attribute each sentence to its own source rather than presenting one wording as universal.
- The SP 800-53 Rev. 5 wording emphasizes uniform enforcement and constraints on subject actions, while the SP 800-44 Version 2 wording describes labels and clearances. Both express different facets of MAC.
- NIST SP 800-162 was published in January 2014, and the publication page lists updates as of 2019-08-02. Its ABAC definition is useful context, but it should not be read as a complete taxonomy of access-control models. NIST SP 800-162 publication page
The short version
MAC is a centrally governed access-control policy. Access depends on policy decisions made by an authority rather than by the owner of a resource, and authorized users are limited in how they can pass on access, change labels, or modify the rules.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

