Home > Research > Publications & Outputs > General Access Control Guidance for Cloud Systems
View graph of relations

General Access Control Guidance for Cloud Systems: SP 800-210(Draft)

Research output: Other contribution

E-pub ahead of print
Close
Publication date1/04/2020
<mark>Original language</mark>English

Abstract

This document presents cloud access control characteristics and a set of general access control guidance for cloud service models: IaaS (Infrastructure as a Service), PaaS (Platform as a Service), and SaaS (Software as a Service). Different service delivery models require managing different types of access on offered service components. Such service models can be considered hierarchical, thus the access control guidance of functional components in a lower-level service model are also applicable to the same functional components in a higher-level service model. In general, access control guidance for IaaS is also applicable to PaaS and SaaS, and access control guidance for IaaS and PaaS is also applicable to SaaS. However, each service model has its own focus with regard to access control requirements for its service.