MAC is the strictest of the three frameworks. Authorisation in this model is based on a **strict need-to-know basis**. Access to information must be *granted manually by a central authority or system administrator*. For example, MAC is commonly applied in law enforcement, military, and other government agencies where users must request access through a chain of command. MAC is *also known as non-discretionary control* because access isn’t given at the discretion of the data owner.
![[Mandatory Access Control.png]]