Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Guidelines for Access Control System Evaluation Metrics



Chung Tong Hu, Karen Scarfone


The purpose of this document is to provide Federal agencies with background information on access control (AC) properties, and to help access control experts improve their evaluation of the highest security AC systems. This document discusses the administration, enforcement, performance, and support properties of AC mechanisms that are embedded in each AC system. (Even though this document covers most of the essential AC properties, the listed properties are not necessarily complete.) This document extends the information in NIST IR 7316, Assessment of Access Control Systems [NISTIR 7316], which demonstrates the fundamental concepts of policy, models, and mechanisms of AC systems.
NIST Interagency/Internal Report (NISTIR) - 7874
Report Number


Access Control, Authorization, Policy, Computer Security


, C. and Scarfone, K. (2012), Guidelines for Access Control System Evaluation Metrics, NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online], (Accessed May 24, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created September 14, 2012, Updated June 9, 2020