ABAC
Attribute-Based Access Control (ABAC) makes access decisions based on user, resource, and environmental attributes.
Attribute-Based Access Control (ABAC) makes access decisions based on specific attributes. It considers properties of the user, the resource, the action, and the environment.
How it works
Each access request is checked against rules that combine multiple attributes. User attributes include department, function or security clearance. Resource attributes include classification, owner or project. Contextual details such as location, device and time of day are also considered. A rule could state, for example: legal department staff can read confidential contracts, but only from a managed device.
A hospital, for instance, manages patient data across several clinics. With RBAC, this would require a separate role for every combination of function and clinic. With ABAC, one rule applies: nurses see the data for patients on their own ward. If a nurse changes ward, their access adjusts automatically.
What to look out for
- ABAC is only as good as its attributes. These must be current and reliable.
- Rules can become complex very quickly. Document and test them carefully.
- Define who is allowed to maintain attributes. A change can have wide-ranging consequences.
- Check whether your applications support ABAC.
How it differs from RBAC
RBAC assigns permissions via fixed roles and is simpler to understand. ABAC is more flexible and considers the context of the access request. In practice, many organisations combine both models. Roles form the foundation, and attributes refine the access.
Switzerland and regulation
In the healthcare and banking sectors, fine-grained access to personal data is vital. ABAC can help implement the requirements of the revFADP (revised Federal Act on Data Protection) and FINMA regarding the principle of least privilege.
Typical mistakes
A common mistake is using attributes from different, unsynchronised systems. This can lead to incorrect access decisions. Another error is failing to log access decisions. During an audit, it is then impossible to show why access was granted.
Relevance for the SOC
The decisions of an ABAC system are a valuable log source. Denied access to sensitive data can indicate an attack.
How we implement it
In the SOC, we analyse access decisions as a log source. We are happy to discuss architecture questions as part of our Security Consulting.