an access control paradigm whereby access rights are granted to users through the use of policies which combine attributes together. The policies can use any type of attributes (user attributes, resource attributes, environment attribute etc.
Sources:
NIST SP 800-192
under ABAC
High-level requirements that specify how access is managed and who may access information under what circumstances.
Sources:
NIST SP 800-192
Policies that describe who is allowed to access the data and/or which parts of the data.
Sources:
NIST SP 800-226
under access control policies
The set of rules that define the conditions under which an access may take place.
Sources:
NISTIR 7316