Risk-based access control: A dynamic method of controlling access to resources based on the risk associated with a user’s access at any given time. This approach considers factors such as the value of the resources being accessed, the current security state of the system, and the identity or role of the user in making access decisions. This ensures that higher-risk access scenarios require stricter security measures or controls.
Categories: CC D3: Access Controls Concepts | CCSP D4: Cloud Application Security | CISM D3: Information Security Program | CISSP D1: Security and Risk Management | Security+ D1: General Security Concepts | SSCP D3: Risk Identification Monitoring and Analysis
« Back to Glossary Index