MLchartDataset catalogue

Attribute-based access control (ABAC)

Term · Cybersecurity · MLC-T-CYB-000299

1. An access control method where subject requests to perform operations on objects are granted or denied based on assigned attributes of the subject, assigned attributes of the object, environment conditions, and a set of policies that are specified in terms of those attributes and conditions.

2. An access control approach in which access is mediated based on attributes associated with subjects (requesters) and the objects to be accessed. Each object and subject has a set of associated attributes, such as location, time of creation, access rights, etc. Access to an object is authorized or denied depending upon whether the required (e.g., policy-defined) correlation can be made between the attributes of that object and of the requesting subject.

3. Access control based on attributes associated with and about subjects, objects, targets, initiators, resources, or the environment. An access control rule set defines the combination of attributes under which an access may take place.
See also identity, credential, and access management (ICAM).

4. an access control paradigm whereby access rights are granted to users through the use of policies which combine attributes together. The policies can use any type of attributes (user attributes, resource attributes, environment attribute etc.

Table 1. Record
IdentifierMLC-T-CYB-000299
FieldCybersecurity
AbbreviationABAC
ReferencesNIST SP 800-162; NIST SP 800-95 from Common Criteria v2.3, Part 2; CNSSI 4009-2015; NIST SP 800-192; NIST CSRC Glossary
See alsoIdentity, Credential, and Access Management (ICAM)
Record as JSON
{
  "id": "MLC-T-CYB-000299",
  "term": "Attribute-based access control (ABAC)",
  "field": "Cybersecurity",
  "definition": "1. An access control method where subject requests to perform operations on objects are granted or denied based on assigned attributes of the subject, assigned attributes of the object, environment conditions, and a set of policies that are specified in terms of those attributes and conditions.\n\n2. An access control approach in which access is mediated based on attributes associated with subjects (requesters) and the objects to be accessed. Each object and subject has a set of associated attributes, such as location, time of creation, access rights, etc. Access to an object is authorized or denied depending upon whether the required (e.g., policy-defined) correlation can be made between the attributes of that object and of the requesting subject.\n\n3. Access control based on attributes associated with and about subjects, objects, targets, initiators, resources, or the environment. An access control rule set defines the combination of attributes under which an access may take place.\nSee also identity, credential, and access management (ICAM).\n\n4. an access control paradigm whereby access rights are granted to users through the use of policies which combine attributes together. The policies can use any type of attributes (user attributes, resource attributes, environment attribute etc.",
  "abbreviation": "ABAC",
  "see_also": [
    "Identity, Credential, and Access Management (ICAM)"
  ],
  "references": [
    "NIST SP 800-162",
    "NIST SP 800-95 from Common Criteria v2.3, Part 2",
    "CNSSI 4009-2015",
    "NIST SP 800-192",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/attribute-based-access-control-abac/"
}

Record 298 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.