An Access Control System (ACS) is essential for IT security. It ensures that only authorized users can access specific resources. Implementing an ACS enhances data security and protects against unauthorized access.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
An access control system decides which subjects may access which resources and enforces those decisions technically.
The approach grew from the security need to limit access to information and systems in a traceable way. NIST brings models, roles, and policies together in an institutional framework; no single originator of the general concept is established.
Imagine a gate: a requesting identity presents its attributes, a policy evaluates context and permission, and an enforcement component allows or denies the requested action. Logging makes the decision auditable later.
A person, service, or device whose request is evaluated.
The protected object or service targeted by an action.
Rules define the conditions under which an action is allowed.
Technical components apply the decision consistently and may record it.
The concept supports the design of roles, service access, and privacy boundaries. Key questions concern accountable ownership, least privilege, and how changes or incorrect decisions are detected.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.