Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-178

A Comparison of Attribute Based Access Control (ABAC) Standards for Data Service Applications: Extensible Access Control Markup Language (XACML) and Next Generation Access Control (NGAC)

Date Published: October 2016


David Ferraiolo (NIST), Ramaswamy Chandramouli (NIST), Vincent Hu (NIST), Richard Kuhn (NIST)



access control mechanism; access control model; access control policy; attribute based access control (ABAC); authorization; Extensible Access Control Markup Language (XACML); Next Generation Access Control (NGAC); access control; privilege
Control Families

Access Control


Download URL

Supplemental Material:
None available

Related NIST Publications:
SP 800-162
IR 7987 Rev. 1
IR 7316
ITL Bulletin

Document History:
12/02/15: SP 800-178 (Draft)
10/03/16: SP 800-178 (Final)


Security and Privacy

access authorization, access control