Policy Enforcement Point (PEP)

The gatekeeper between a subject and a resource that passes each access request to a decision point and applies the verdict it receives by allowing or refusing the access.

A policy enforcement point is the component that stands between a subject and the resource it wants, and applies access decisions. NIST SP 800-162 describes it as enforcing policy decisions in response to a subject’s request, with the decisions themselves made by the policy decision point. The ISC2 exam outline names it as an example of access policy enforcement under objective 5.4. In practice a PEP can be an application or API gateway, a proxy server, a firewall or an agent on an endpoint.

In NIST SP 800-207 the PEP enables, monitors and eventually terminates connections between a subject and an enterprise resource, taking its instructions from the policy administrator, and may be split into a client agent and a resource gateway. A PEP is only as useful as it is unavoidable: if a path to the resource bypasses it, policy is not enforced on that path. That is the same completeness idea found in the reference monitor, and it is why zero trust designs place enforcement as close to each resource as they can.

Exam relevance: a scenario is likely to describe a gateway that checks each request with a central policy service and ask what role it plays. Candidates are expected to identify the enforcement point, and to recognise that a route around it undermines the design.