Access Control
Access Control is the set of mechanisms and policies used to control access to systems, applications and data. The aim is that only authorized users and services can use specific resources, and only in the intended way.
Classic models are discretionary access control (DAC) and mandatory access control (MAC); in organizations today, role-based (RBAC) and attribute-based (ABAC) approaches dominate. Increasingly, context information such as location, device state or risk assessment flows into the decision, making access control dynamic instead of static.
Access control is the umbrella term; in practice it is implemented through the interaction of authentication (Who is accessing?) and authorization (What is permitted?). Organizationally, access control is anchored in Identity and Access Management, which keeps rules, roles and processes consistent across all systems.