MLchartDataset catalogue

Risk Adaptive (Adaptable) Access Control

Term · Cybersecurity · MLC-T-CYB-003591

1. In RAdAC, access privileges are granted based on a combination of a user’s identity, mission need, and the level of security risk that exists between the system being accessed and a user. RAdAC will use security metrics, such as the strength of the authentication method, the level of assurance of the session connection between the system and a user, and the physical location of a user, to make its risk determination.

2. A form of access control that uses an authorization policy that takes into account operational need, risk, and heuristics.

3. Access privileges are granted based on a combination of a user’s identity, mission need, and the level of security risk that exists between the system being accessed and a user. RAdAC will use security metrics, such as the strength of the authentication method, the level of assurance of the session connection between the system and a user, and the physical location of a user, to make its risk determination.

Table 1. Record
IdentifierMLC-T-CYB-003591
FieldCybersecurity
AbbreviationRAdAC
ReferencesNIST SP 800-95 from TAT-06284; CNSSI 4009-2015; CNSSI 4009-2022; NIST SP 800-160 Vol. 2 [Superseded] from NIST SP 800-95; NIST SP 800-160 Vol. 2 Rev. 1 from NIST SP 800-95; NIST CSRC Glossary
Record as JSON
{
  "id": "MLC-T-CYB-003591",
  "term": "Risk Adaptive (Adaptable) Access Control",
  "field": "Cybersecurity",
  "definition": "1. In RAdAC, access privileges are granted based on a combination of a user’s identity, mission need, and the level of security risk that exists between the system being accessed and a user. RAdAC will use security metrics, such as the strength of the authentication method, the level of assurance of the session connection between the system and a user, and the physical location of a user, to make its risk determination.\n\n2. A form of access control that uses an authorization policy that takes into account operational need, risk, and heuristics.\n\n3. Access privileges are granted based on a combination of a user’s identity, mission need, and the level of security risk that exists between the system being accessed and a user. RAdAC will use security metrics, such as the strength of the authentication method, the level of assurance of the session connection between the system and a user, and the physical location of a user, to make its risk determination.",
  "abbreviation": "RAdAC",
  "references": [
    "NIST SP 800-95 from TAT-06284",
    "CNSSI 4009-2015; CNSSI 4009-2022",
    "NIST SP 800-160 Vol. 2 [Superseded] from NIST SP 800-95; NIST SP 800-160 Vol. 2 Rev. 1 from NIST SP 800-95",
    "NIST CSRC Glossary"
  ],
  "url": "https://mlchart.com/terminology/cybersecurity/risk-adaptive-adaptable-access-control/"
}

Record 3,591 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.