Context-dependent access control
Access control in which the decision depends on the circumstances of the request, such as time, location, device or the sequence of earlier actions, rather than on the data requested.
Context-dependent access control allows or refuses a request according to the situation in which it is made. Examples include a payroll function available only during business hours, an administrative console reachable only from the internal network, or a transaction step that opens only after the previous step has completed. A stateful inspection firewall is commonly given as a network example, since it admits inbound traffic when it belongs to a connection already opened from inside.
The partner term is content-dependent access control, which decides from the values inside the object. Context describes the request, not the data. The same idea sits behind the environment attributes of attribute-based access control and the signals weighed in risk-based access control, where location, device health or unusual behaviour can raise the assurance a request needs. Location and time are commonly treated as context that an access decision weighs, not as authentication factors of the same kind as a password or a token.
Exam relevance: questions in this area tend to give a restriction and ask which type it is. Conditions about when, where, from which device or after which prior step point to context-dependent control; a condition on a value inside the record points to content-dependent control. Candidates are also expected not to count location or time as an extra authentication factor.