Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

m-NGAC: Transcending Traditional Database Security Models | NIST Publishes IR 8611

NIST has released Internal Report (IR) 8611, m-NGAC: Transcending Traditional Database Security Models.

NIST has released Internal Report (IR) 8611, m-NGAC: Transcending Traditional Database Security Models, which explores a new approach to fine-grained access control by embedding the ANSI/INCITS Next Generation Access Control (NGAC) framework directly within the database. This paper offers a fresh perspective on an increasingly important question in data security: How can we make access control more precise, consistent, and difficult to bypass?

Rather than relying on applications to enforce security policies, m-NGAC brings policy enforcement closer to the data and helps provide consistent protection across applications, reporting tools, SQL editors, and direct database connections. This publication examines how m-NGAC can provide fine-grained control down to the row, column, and field level while supporting centralized policy management across multiple databases. It also explores how the approach differs from traditional database controls and other NGAC-based solutions, including its ability to preserve the original query logic while protecting restricted data.

Read IR 8611, m-NGAC: Transcending Traditional Database Security Models, to explore the approach and its potential for modern database security.

Released August 27, 2026
Was this page helpful?