← Cybersecurity Alphabet Soup

PBAC

Policy-Based Access Control

identityhard

PBAC pulls authorization decisions out of individual applications and into centrally written policies that a decision engine evaluates at request time, weighing roles, attributes, and context together. Instead of each app hardcoding its own access rules, one policy set governs many systems, keeping authorization consistent and auditable. It matters most in large environments where scattered, inconsistent access logic becomes a security and compliance liability.

Sources

More in identity