SECAI Core · phase 10 of 15 · noun
Attribute-based access control
An access control technique that evaluates a set of attributes that each subject possesses to determine if access should be granted.
The Explain card
- Plain English
- Attribute-based access control (ABAC) grants or denies access by evaluating a set of attributes about the subject, the resource and the context, rather than a fixed role.
- Example
- A policy says a user may query the customer-data retrieval index only if their department is Support, their clearance is Confidential or higher, the request comes from the corporate network, and the data's region matches the user's region. Change any attribute and the answer changes.
- Why it matters
- AI systems touch data with many sensitivity dimensions. ABAC expresses fine-grained rules such as "only during business hours" or "only for EU data" that roles alone cannot capture.
- Hook
- Not who you are, but everything about you, right now.
Word knowledge
How the word is built, where it came from, and what it sits beside in memory.
In a sentence
The gateway uses attribute-based access control to restrict the diagnostic console to authorized engineers using managed laptops.
Why these words
- attribute Latin attributum, something assigned names a recorded property used by the system
- based Greek basis through Latin and French, foundation links the method to the information on which it relies
- access Latin accessus, approach or entrance identifies the use of a protected resource
- control Medieval Latin contrarotulus, a checking register names the broader security practice
Where it came from
- Origin
- English computer-security compound formed from attribute-based and access control
- Entered the language
- 2000s
- What changed
- Attribute moved from an assigned quality to a machine-readable property, while access control became a standard computing term for regulating resource use.
How it is spelled
- Pattern
- Attribute-based is hyphenated because it is a compound modifier before access control.
- Pattern
- Access control remains an open compound.
Spelled like
- role-based access control
- rule-based access control
- identity-based access control
Broken into chunks
-
attribute-based
- role-based
- policy-based
- identity-based
-
access control
- admission control
- export control
- traffic control
What it sits beside
Same subject
- authorization
- access-control policy
- policy decision point
- least privilege
Same shape
- role-based access control
- risk-based authentication
- policy-based management
access control models
- attribute-based access control
- role-based access control
- mandatory access control
- discretionary access control
security attributes
- user clearance
- device status
- resource classification
- request time
Where it sits in the deck
Phase 10: Identity, Access, and Cryptographic Foundations
Before examining threats to systems, establish the foundational security primitives — identity, authentication, authorisation, and the cryptography underpinning them.