Access control is crucial for the security of IT systems. It ensures that only authorized users can access sensitive data and system resources. Various methods, such as Role-Based Access Control (RBAC) or Multi-Factor Authentication (MFA), are commonly employed.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Access control decides whether an identified person or technical service may perform a particular action on a protected resource. It translates security rules into auditable permit-or-deny decisions.
The approach evolved with shared computer systems from a fundamental security question: who is allowed to do what? Early models focused on statically assigned privileges; NIST introduced Role-Based Access Control as a general model in 1992 and later advanced approaches such as Attribute-Based Access Control for richer contextual decisions.
Treat every access attempt as a request with four parts: subject, resource, intended action, and context. A policy describes the permitted combinations. A decision point evaluates identity, roles, or attributes against that rule; an enforcement point allows or blocks the action. Logs preserve the decision so that privileges and incidents can be examined later.
A person or service wants to access a protected object or function.
A rule describes permitted actions, conditions, and restrictions.
The access decision is evaluated separately and applied at the actual access point.
Models such as RBAC and ABAC structure decisions around roles or contextual characteristics.
Identities receive only the permissions they need for their responsibilities.
Access control is central whenever data, APIs, or infrastructure must be protected from unauthorized use. Its effectiveness depends on current identities, clear policies, regular privilege reviews, and reliable logging; ever-growing exceptions and overly broad roles weaken the protection model.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.