NIST SP 800-162, Guide to Attribute Based Access Control (ABAC) Definition and Considerations
NIST SP 800-162 is a guide published by the National Institute of Standards and Technology (NIST) that defines and explains attribute based access control (ABAC), a method of deciding who can access information based on characteristics called attributes. It is intended to help federal agencies understand ABAC concepts and considerations for using this approach. It provides definitions and considerations rather than mandatory requirements, so readers should confirm how it applies to their specific systems against current official sources.
NIST Special Publication 800-162, authored by V. Hu and others and maintained by NIST, provides Federal agencies with a definition of attribute based access control (ABAC), described as a logical access control methodology. The publication addresses ABAC definition and considerations to inform agency understanding and planning. As a NIST special publication of this type, it is generally advisory guidance rather than a binding control baseline; practitioners should verify the current revision (the evidence references an updated final release) and confirm its scope and applicability against the authoritative text at csrc.nist.gov.
Why it matters
Access control is foundational to protecting federal information systems, and the choice of access control model directly affects how precisely an organization can enforce policy over who reaches which data. NIST SP 800-162 matters because it gives federal agencies a common, authoritative vocabulary and set of considerations for attribute based access control (ABAC), an approach that decides access based on characteristics (attributes) rather than static role or identity lists alone. For compliance officers and system security personnel evaluating access control strategies, having a NIST-published reference helps ground design discussions in shared definitions rather than vendor-specific terminology.
Because SP 800-162 is advisory guidance rather than a binding control baseline, it should not be mistaken for a mandate or an authorization requirement. It informs understanding and planning; it does not by itself impose obligations the way a control catalog or a contractual clause would. Readers should treat it as a conceptual and planning resource and confirm how any ABAC design maps to the actual access control requirements that apply to their systems, which are set out in the governing control baselines and agency tailoring, not in this guide.
Getting the framing right also avoids a common error: assuming that adopting an ABAC model described in this publication automatically satisfies an agency's access control obligations. The guide describes a methodology and considerations; demonstrating that a specific implementation meets applicable requirements remains a separate assessment that must be verified against the current authoritative text and the controls that govern the system in question.
Who it's relevant to
Inside SP 800-162
Common questions
Answers to the questions practitioners most commonly ask about SP 800-162.