The Information Protection Life Cycle (IPLC) and Information Protection Framework describe how information should be protected across three stages: acquire & assess, active use life, and disposition. The “main sequence” is Active Use Life, when information objects are actively used and therefore most exposed to access-related risks. Within this stage, the first major control category is Control Access, reflecting that information varies widely in intended openness: some content is deliberately public (e.g., Wikipedia under a Creative Commons license, works in the public domain), while other information is created to be restricted (e.g., trade secrets, contracts, copyrighted works, patents, PII, and financial statements). For sensitive information, access must be granular so that only authorized users on trusted devices can read, modify, or delete it.
Access control starts with authentication, which increasingly relies on contextual signals beyond user identity—device identity, environmental attributes (location, IP, geo-velocity, time), and session risk analytics informed by behavior and threat intelligence. Identity federation enables authentication to be trusted across domains. Despite substantial innovation and attention on authentication mechanisms (apps, push, hardware tokens, biometrics, FIDO, PKI), authentication is only the first step.
Authorization determines whether a user, app, or device may access specific resources. It has evolved from static ACLs to attribute- and policy-driven approaches that evaluate user, device, and resource metadata. Authorization is the core of access control, ranging from relatively simple consumer banking scenarios to stringent enterprise and government use cases, including Mandatory Access Control aligning classification with clearance. Standards and models include RBAC, ABAC, XACML, OAuth (and OpenID Connect/UMA), SAML, and LDAP, but heterogeneous and proprietary implementations create “last mile” integration challenges, especially for LOB applications.
Data Access Governance tools sustain control by validating classifications, managing ownership, normalizing permissions, recertifying access, detecting anomalies, monitoring changes and user patterns, and supporting request/approval workflows. Recommended actions include evaluating IPLC coverage, assessing authentication/authorization/governance capabilities across on-prem and cloud, and prioritizing control upgrades using risk management.
See All Locations
See All Locations