Policy Information Point (PIP)
An attribute source consulted during an access decision: it returns facts about the subject, resource, action or environment that the policy decision point needs to evaluate a rule.
A policy information point is where a policy decision point gets the facts its rules refer to. NIST SP 800-162 describes it as the retrieval source of attributes, or other data required for policy evaluation. XACML uses the same term. The attributes can describe the subject (department, clearance, employment status), the object (owner, sensitivity label), the action, or the environment (time, location, threat level). A PIP is commonly an existing system rather than a new one: a directory service, an HR system, an asset inventory, or an endpoint management platform that reports device health.
The PIP is what makes attribute-based access control work, and it is also where that model is exposed. A decision is only as sound as the attributes behind it, so stale or tampered attribute data yields wrong decisions from correct policy. Attribute sources therefore need their own integrity, freshness and access controls. The PIP supplies facts and the policy administration point supplies rules; neither of them decides.
Exam relevance: a scenario is likely to describe an access decision that went wrong because a leaver was still marked active in the HR feed, or to ask which component provides a user’s clearance to the decision point. Candidates are expected to identify the PIP and to treat attribute quality as a control concern in its own right.