Risk Adaptive (Adaptable) Access Control
Term · Cybersecurity · MLC-T-CYB-003591
1. In RAdAC, access privileges are granted based on a combination of a user’s identity, mission need, and the level of security risk that exists between the system being accessed and a user. RAdAC will use security metrics, such as the strength of the authentication method, the level of assurance of the session connection between the system and a user, and the physical location of a user, to make its risk determination.
2. A form of access control that uses an authorization policy that takes into account operational need, risk, and heuristics.
3. Access privileges are granted based on a combination of a user’s identity, mission need, and the level of security risk that exists between the system being accessed and a user. RAdAC will use security metrics, such as the strength of the authentication method, the level of assurance of the session connection between the system and a user, and the physical location of a user, to make its risk determination.
| Identifier | MLC-T-CYB-003591 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | RAdAC |
| References | NIST SP 800-95 from TAT-06284; CNSSI 4009-2015; CNSSI 4009-2022; NIST SP 800-160 Vol. 2 [Superseded] from NIST SP 800-95; NIST SP 800-160 Vol. 2 Rev. 1 from NIST SP 800-95; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003591",
"term": "Risk Adaptive (Adaptable) Access Control",
"field": "Cybersecurity",
"definition": "1. In RAdAC, access privileges are granted based on a combination of a user’s identity, mission need, and the level of security risk that exists between the system being accessed and a user. RAdAC will use security metrics, such as the strength of the authentication method, the level of assurance of the session connection between the system and a user, and the physical location of a user, to make its risk determination.\n\n2. A form of access control that uses an authorization policy that takes into account operational need, risk, and heuristics.\n\n3. Access privileges are granted based on a combination of a user’s identity, mission need, and the level of security risk that exists between the system being accessed and a user. RAdAC will use security metrics, such as the strength of the authentication method, the level of assurance of the session connection between the system and a user, and the physical location of a user, to make its risk determination.",
"abbreviation": "RAdAC",
"references": [
"NIST SP 800-95 from TAT-06284",
"CNSSI 4009-2015; CNSSI 4009-2022",
"NIST SP 800-160 Vol. 2 [Superseded] from NIST SP 800-95; NIST SP 800-160 Vol. 2 Rev. 1 from NIST SP 800-95",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/risk-adaptive-adaptable-access-control/"
}
Record 3,591 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.