NIST RBAC Model
   HOME

TheInfoList



OR:

The NIST RBAC model is a standardized definition of
role-based access control In computer systems security, role-based access control (RBAC) or role-based security is an approach to restricting system access to authorized users. It is an approach to implement mandatory access control (MAC) or discretionary access control ...
. Although originally developed by the
National Institute of Standards and Technology The National Institute of Standards and Technology (NIST) is an agency of the United States Department of Commerce whose mission is to promote American innovation and industrial competitiveness. NIST's activities are organized into physical s ...
, the standard was adopted and is copyrighted and distributed as INCITS 359-2004 by the International Committee for Information Technology Standards (INCITS). The latest version is INCITS 359-2012. It is managed by INCITS committee CS1.


History

In 2000, NIST called for a unified standard for RBAC, integrating the RBAC model published in 1992 by Ferraiolo and Kuhn with the RBAC framework introduced by Sandhu, Coyne, Feinstein, and Youman (1996). This proposal was published by Sandhu, Ferraiolo, and Kuhn and presented at the ACM 5th Workshop on Role Based Access Control. Following debate and comment within the RBAC and security communities, NIST made revisions and proposed a U.S. national standard for RBAC through the INCITS. In 2004, the standard received ballot approval and was adopted as INCITS 359-2004. Sandhu, Ferraiolo, and Kuhn later published an explanation of the design choices in the model. In 2010, NIST announced a revision to RBAC, incorporating features of attribute-based access control (ABAC). {{cite journal , author = Kuhn, D.R., Coyne, E.J., and Weil, T.R. , title = Adding Attributes to Role Based Access Control , journal = IEEE Computer , volume = 43 , issue = 6 , date=June 2010 , pages = 79–81 , publisher = IEEE Press , url = http://csrc.nist.gov/groups/SNS/rbac/documents/kuhn-coyne-weil-10.pdf , doi=10.1109/mc.2010.155 , s2cid = 17866775


See also

*
Role-based access control In computer systems security, role-based access control (RBAC) or role-based security is an approach to restricting system access to authorized users. It is an approach to implement mandatory access control (MAC) or discretionary access control ...


References


External links


NIST RBAC web site

INCITS web site
Computer access control Computer security models Data security Firewall software Packets (information technology)