SECAI Core · phase 10 of 15 · noun

Attribute-based access control

An access control technique that evaluates a set of attributes that each subject possesses to determine if access should be granted.

The Explain card

Plain English
Attribute-based access control (ABAC) grants or denies access by evaluating a set of attributes about the subject, the resource and the context, rather than a fixed role.
Example
A policy says a user may query the customer-data retrieval index only if their department is Support, their clearance is Confidential or higher, the request comes from the corporate network, and the data's region matches the user's region. Change any attribute and the answer changes.
Why it matters
AI systems touch data with many sensitivity dimensions. ABAC expresses fine-grained rules such as "only during business hours" or "only for EU data" that roles alone cannot capture.
Hook
Not who you are, but everything about you, right now.

Word knowledge

How the word is built, where it came from, and what it sits beside in memory.

In a sentence

The gateway uses attribute-based access control to restrict the diagnostic console to authorized engineers using managed laptops.

Why these words
  • attribute Latin attributum, something assigned names a recorded property used by the system
  • based Greek basis through Latin and French, foundation links the method to the information on which it relies
  • access Latin accessus, approach or entrance identifies the use of a protected resource
  • control Medieval Latin contrarotulus, a checking register names the broader security practice
Where it came from
Origin
English computer-security compound formed from attribute-based and access control
Entered the language
2000s
What changed
Attribute moved from an assigned quality to a machine-readable property, while access control became a standard computing term for regulating resource use.
How it is spelled
Pattern
Attribute-based is hyphenated because it is a compound modifier before access control.
Pattern
Access control remains an open compound.

Spelled like

  • role-based access control
  • rule-based access control
  • identity-based access control
Broken into chunks
  • attribute-based
    • role-based
    • policy-based
    • identity-based
  • access control
    • admission control
    • export control
    • traffic control
What it sits beside

Same subject

Same shape

access control models

security attributes

  • user clearance
  • device status
  • resource classification
  • request time

Where it sits in the deck

Phase 10: Identity, Access, and Cryptographic Foundations

Before examining threats to systems, establish the foundational security primitives — identity, authentication, authorisation, and the cryptography underpinning them.