RESPOND TO THESE DISCUSSION POST BASED ON THE TOPIC “Access control is a security measure that ensures that all types of data are protected from unauthorized disclosure or modification. Access control approaches determine how users interact with data and other network resources.
 In an initial post:
Explain a scenario where you would apply one of the four access control measures. Why would you select one over the others?
Continue the discussion by evaluating how mandatory vacation can be used as a tool to detect fraud and help employees release their work stress.
Then, respond to your classmates. Did you agree with their opinion of the most important access control measure to use in their scenario? Why or why not?.” (TWO (2) PARAGRAPHS EACH WITH REFERENCES ON EACH OF THEM SEPARATELY, NOT TOGETHER)

1.dAvD dUfLA  
My first thought was of an ERP system. Separation of duties is a classic method to manage conflict of interest (Gregg, Nam, Northcutt, Pokladnik, n.d.). The scenario that comes to mind is related to sales staff and accounting staff assigned access with Role Based Access Control (RBAC). The process of defining roles is usually based on analyzing the fundamental goals and structure of an organization and is usually linked to the security policy (, 2016). In an ERP, sales staff would be assigned roles to create orders for customers and take payment. This means sales staff would only have access to customer data and order data. Accounting staff would have access to payment processor data, credit card records from a company like, and access to the ERP accounting data. This would separate the duties between the person who accepts payment and a person who reviews and validates records matching orders. This would prevent sales staff from potentially giving away products to friends and family by having a review process for orders. Sales staff wouldn’t have the ability to access accounting modules to cover fraudulent activity.
RBAC is also very useful for seasonal staff and temp staff. The use of seasonal staff signifies and spike in business which indicates a need to rapidly scale up and scale down. RBAC allows administrators to quickly assign predefined roles to staff that may be hired and start employment all within a very short window. 

Wk4
At work we have a program called backoffice were regular store employees, assistant managers and the store manager can access different functions on the POS to gain different information. When an employee is set up in the POS they are given an access level either access 1, which allows full access to functions in back office, access 2, which allows most functions to be accessed in backoffice, or access level 3, which has very VERY limited access and allows the user to access the most basic of functions in back office. I would consider this to be Role Based Access Control because you are given your access level based on your position in the store. Store Managers have level 1, Assistant Managers are level 2, and all other employees are level 3. This helps to ensure that the correct tasks can be accessed by the correct position and certain information is not seen or accessed by those not authorized to see it.
I am a strong believer that everyone should be allowed vacation time throughout somepoint in the year. I found it interesting that it could be used to detect fraud because managers can use the time that the employee has off to investigate and see if they are doing anything that could harm the company. It is also a way for employees to release their work stress because it gives them time away from work to be with thier familes and to relax

Discss
I work in many regulatory environments, and so we have multiple programs institute rule-based access control, in addition to the other three types.  The rule-based access control has been employed in certain evidence databases whereby staff have access to their group’s evidence (role-based), however, access to certain evidence within each group may only be allowed if you have certain rights (rule-based), e.g., are on an additional list.  In addition, managers from each group (role-based), have the ability to “invite” staff from other groups to view their protected material (a mixture of role- and rule-base access control).
To expand, we generally break up individuals by departments and sometimes by subgroups within the department.  In some instances we have created groups of “managers”.  This second group is normally created to assist with an approval process.  The grouping is generally role-based as described initially, however, the approval process described would most likely have characteristics of a roll- and rule-based configuration.

