Policy Decision Point (PDP)

The component that evaluates an access request against the applicable policy and attributes and returns a verdict, such as permit or deny. It decides; a separate enforcement point acts on it.

A policy decision point evaluates an access request against the policy that applies to it and renders a decision, commonly permit or deny. NIST SP 800-162 describes it as computing access decisions by evaluating the applicable policies, and the OASIS XACML standard uses the same term. The ISC2 exam outline names the policy decision point, beside the policy enforcement point, as an example of access policy enforcement under objective 5.4. The PDP uses the policy authored at the policy administration point and the attributes supplied by the policy information point, and returns its answer to the policy enforcement point.

Separating decision from enforcement lets one central PDP serve many enforcement points, so the same policy holds across applications, APIs and network paths, which suits attribute-based access control. The cost is dependency: if the PDP cannot be reached, the enforcement points need a defined failure behaviour, and for access decisions that is commonly to deny. NIST SP 800-207 divides the PDP of zero trust into the policy engine, which decides, and the policy administrator, which acts on the decision.

Exam relevance: questions in this area tend to turn on which component decides and which enforces. Candidates are expected to keep the PDP as the decider, and the PEP as the component in the request path that carries the decision out.