Risk-based access control
An access control approach that estimates the risk of each request from its context, then allows it, asks for stronger authentication, or denies it. Also called adaptive access control.
Risk-based access control evaluates each request when it is made and estimates its risk from contextual signals: the device and its health, the network and location, the time, the sensitivity of the resource, and whether the activity matches the user’s usual pattern. Low-risk requests proceed, higher-risk requests can trigger step-up authentication such as an extra multi-factor authentication prompt, and the riskiest are denied. It is also called adaptive access control, and the ISC2 exam outline lists “Risk based access control” in 5.4.
It is close to attribute-based access control, since both evaluate attributes at request time. ABAC matches attribute values against written rules, while a risk-based system combines signals into a likelihood and acts on thresholds. Both suit the per-request evaluation of zero trust. Location and time here are context the decision weighs, not extra authentication factors. The weakness is transparency: a score built from many signals can be hard to explain or audit, and a badly tuned threshold either burdens legitimate users or lets risky requests through.
Exam relevance: a scenario in which a sign-in from an unfamiliar country or device prompts an extra verification step is likely to point to risk-based or adaptive access control. Candidates are expected to separate it from ABAC’s rule matching and to treat location as context rather than as a factor.