As military organizations explore attribute-based access control as a method to restrict unauthorized access to IT networks, they must consider potential drawbacks.
Put simply, ABAC means that a system user has access only to the data and services they need to do their work, as defined by their role within the organization. An intelligence analyst, for example, would have access to layers of information that a clerical employee would not. Those layers of access would be defined by role rather than individual.
For much more on ABAC, download our free report, Authorized Personnel Only.
However, there are gray areas, especially when people have multiple roles. For example Jason Martin, civilian deputy for the Defense Information Systems Agency services directorate, suggested the example of an Army reservist who is also a contractor. Those two roles would provide two different access profiles.
“What we do is make sure those attributes are clearly defined and up to date for both personas,” Martin said. ABAC, however, would notice any improper activity the person engaged in while logged in as a given persona.
Related: Could attribute-based access prevent an OPM-level breach?




