Attribute-Based Access Control
What is Attribute-Based Access Control?
An access control paradigm that grants or denies access based on policies evaluating attributes of users, resources, actions, and the environment.
Terms that appear alongside attribute-based access control
Each of these is named in at least one of the same controls as attribute-based access control. The number is how many controls name both.
- access control 9 shared controls
- role based access control 6 shared controls
- zero trust 5 shared controls
- privileged access management pam 5 shared controls
- role based access control rbac 5 shared controls
- privileged access management 5 shared controls
- access management 5 shared controls
- nist 5 shared controls
Frameworks that govern attribute-based access control
What the standards actually require on attribute-based access control
Requirements naming attribute-based access control across 6 standards, quoted from the control text.
Assign permissions via groups, permission sets or attribute-based access control rather than to individual users to simplify management and reduce permission sprawl.
SEC02-BP06 · Employ user groups and attributes →ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities.
ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO · ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM →Security Dimension 1 Access Control per X.805 Clause 6.1: Access Control protects against unauthorized use of network resources. Access Control ensures that only authorized personnel or devices are allowed access to network elements + stored information + info...
X805-Dim1-Access-Control-RBAC-Authorization-Resources-Network-Elements-Services-Applications · ITU-T X.805 Security Dimension 1 - Access Control + Role-Based Access Control (RBAC) + Authorization + Resources + Network Elements + Services + Applications + Access Limitations + Authorized Personnel + Discretionary + Mandatory Access Control →Kuwait NCF Protect function (Access). Access Control and Identity Management aligned with NIST SP 800-53 AC family + ISO 27001 A.9 + Zero Trust principles.
KNCF-Protect-Access-Control-IAM-Privileged-MFA-Zero-Trust-Identity-Lifecycle-IAG-PAM · Kuwait NCF Protect + Access Control + IAM + Privileged + MFA + Zero Trust + Identity Lifecycle →Implement Asset Management + Identity and Access Management + Cryptography per MTCS SS 584. Asset Management (ISO 27001 Annex A.8 alignment) - asset inventory (hardware + software + data + virtual + container + serverless) + asset classification + asset owners...
MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe · MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe →Implement Access Control + Cryptography + Network and Infrastructure Security per MAS TRM Chapters 9 + 10. Chapter 9 Access Control + Cryptography - access control policy + user identification + authentication (Multi-Factor Authentication MFA required for priv...
MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation · MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation →Questions people ask about attribute-based access control
What is Attribute-Based Access Control?
Why is Attribute-Based Access Control important for compliance?
Which compliance frameworks address Attribute-Based Access Control?
Where can I learn more about Attribute-Based Access Control?
See how Attribute-Based Access Control applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.