Field notebook · source record
AC-3(13)
Access ControlAttribute-based Access Control
The statement below is source material, not a generated control summary.
Source statement
Enforce attribute-based access control policy over defined subjects and objects and control access based upon {{ insert: param, ac-03.13_odp }}.
Guidance
Attribute-based access control is an access control policy that restricts system access to authorized users based on specified organizational attributes (e.g., job function, identity), action attributes (e.g., read, write, delete), environmental attributes (e.g., time of day, location), and resource attributes (e.g., classification of a document). Organizations can create rules based on attributes and the authorizations (i.e., privileges) to perform needed operations on the systems associated with organization-defined attributes and rules. When users are assigned to attributes defined in attribute-based access control policies or rules, they can be provisioned to a system with the appropriate privileges or dynamically granted access to a protected resource. Attribute-based access control can be implemented as either a mandatory or discretionary form of access control. When implemented with mandatory access controls, the requirements in [AC-3(3)](#ac-3.3) define the scope of the subjects and objects covered by the policy.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-03.13_odp
attributes
Source guidance- attributes to assume access permissions are defined;
Assessment reference context
Retained, not activated.1 source assessment records and 3 objective nodes are available as reference context. This surface runs none of them.
ac-3.13_objAC-03(13)3 objective nodes
- the attribute-based access control policy is enforced over defined subjects;
- the attribute-based access control policy is enforced over defined objects;
- access is controlled based on {{ insert: param, ac-03.13_odp }}.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion