In DAC, the policy specifies that a subject who has been granted access to information can do the following:
Change security attributes on subjects, objects, information systems or system components
Choose the security attributes to be associated with newly created or revised objects
Change the rules governing access control
ALL
Submit