An organization has implemented a new network management system that requires different levels of access for various job roles. System administrators should have the ability to configure network devices, view configurations, and access logs. On the other hand, network analysts should only have the ability to view configurations and access logs, but not make changes to network devices. Which of the following access control policies should be applied to ensure that the principle of least privilege is upheld?
Discretionary Access Control (DAC)
Mandatory Access Control (MAC)
Role-based access control (RBAC)
Attribute-based access control (ABAC)