Access Control
Kind: mechanism
Layer: Security Core
Record: architecture:access-control
Severity: mandatory
Scope: API, data, infrastructure
Canonical: Ontology
A mechanism that evaluates an access policy for each request to a resource and denies the request when the policy does not allow it.
Listed in Architecture principles, after Authorization and before Role-Based Access Control (RBAC).