An access control policy that is enforced over all subjects and objects in an information system where the policy specifies that a subject that has been granted access to information can do one or more of the following: (i) pass the information to other subjects or objects; (ii) grant its privileges to other subjects; (iii) change security attributes on subjects, objects, information systems, or system components; (iv) choose the security attributes to be associated with newly-created or revised objects; or (v) change the rules governing access control. Mandatory access controls restrict this capability. Source: NIST SP 800-53 Rev 4
Understand more election terms clearly
Get one important election term explained each week, with authoritative sources, practical context and related definitions.
An access control policy that is enforced over all subjects and objects in an information system where the policy specifies that a subject that has been granted access to information can do one or more of the following: (i) pass the information to other subjects or objects; (ii) grant its privileges to other subjects; (iii) change security attributes on subjects, objects, information systems, or system components; (iv) choose the security attributes to be associated with newly-created or revised objects; or (v) change the rules governing access control. Mandatory access controls restrict this capability. Source: NIST SP 800-53 Rev 4
Cite this term
Election Security Glossary. (2026). Discretionary Access Control (dac). In Election Security Glossary. Retrieved August 13, 2026, from https://electionsecurityglossary.com/glossary/discretionary-access-control-dac
Sources
01
Single-source
Get the weekly election term
Receive one cited, source-backed election explanation in your inbox each week.