Attribute-Based Access Control (ABAC)

Attribute-Based Access Control (ABAC) is an access control model in which decisions are made on the basis of attributes that describe the user, resource, action and environment. Such attributes can be, for example, the department, the confidentiality level of a document, the device state, the location or the time of day.

The model is described, among other places, in NIST publication SP 800-162. Policies link attributes into rules, for example: access to financial reports only for employees of the finance department, from a managed device and during business hours. The rules are evaluated by a policy decision point and enforced by a policy enforcement point; XACML is a widespread standardized policy language.

In contrast to Role-Based Access Control (RBAC), which grants rights statically via roles, ABAC decides context-dependently at the moment of access. This enables fine-grained rules without ever new roles, but places high demands on data quality and policy maintenance. In practice, both models are frequently combined. Because ABAC evaluates every access on the basis of the current context, it is considered a suitable model for Zero Trust.