NIST SP 800-162
NIST SP 800-162 is a U.S. government publication that explains attribute based access control (ABAC), a method for deciding who can access what based on characteristics or attributes rather than fixed roles or lists. It was originally developed to give Federal agencies a common definition of ABAC and considerations for using it. It is a guidance document rather than a mandatory rule or a certification standard.
NIST Special Publication 800-162, titled 'Guide to Attribute Based Access Control (ABAC) Definition and Considerations,' provides Federal agencies with a formal definition of attribute based access control as a logical access control methodology. ABAC governs access decisions by evaluating attributes (of subjects, objects, operations, and environment) against policies, in contrast to identity- or role-based models. The document was authored by V. Hu and others and has been maintained through updates (the update 2 final version). For security leadership engagements, it is important to note that SP 800-162 is definitional and advisory guidance describing ABAC concepts and considerations; it does not itself confer compliance or certification, and adopting ABAC per this guide depends on organizational policy design, attribute management, and enforcement infrastructure.
Why it matters
Access control is one of the foundational disciplines a security leader must get right, and NIST SP 800-162 matters because it provides a common, authoritative vocabulary for attribute based access control (ABAC). Many organizations rely on role-based models that grow brittle over time as roles multiply and access sprawls. ABAC, as defined in this guide, offers a way to make access decisions based on attributes of subjects, objects, operations, and environment evaluated against policy. For a virtual or fractional CISO helping a client rationalize an access model, having a shared reference definition helps align stakeholders who may otherwise use the term ABAC loosely or inconsistently.
It is equally important to understand what this document is not. SP 800-162 is definitional and advisory guidance; it does not itself confer compliance or certification, and it is not a mandatory rule. A common mistake is to treat adopting the guide as an outcome in itself, when in practice the value of ABAC depends heavily on organizational policy design, disciplined attribute management, and the enforcement infrastructure available to evaluate policies at runtime. A security leader should frame this document as a starting point for design decisions rather than a deliverable that guarantees improved access governance.
Because SP 800-162 was originally developed to give Federal agencies a shared definition of ABAC, its concepts carry particular weight in government and government-adjacent environments, but the model it describes is applicable more broadly. Where an organization's identity and access maturity is low, the effort to define, source, and maintain reliable attributes may exceed the near-term benefit, so a candid assessment of organizational readiness typically precedes any recommendation to move toward an ABAC model.
Who it's relevant to
Inside NIST SP 800-162
Common questions
Answers to the questions practitioners most commonly ask about NIST SP 800-162.