eXtensible Access Control Markup Language (XACML)
An OASIS standard defining an XML policy language for attribute-based authorisation, a request and response format, and a reference architecture of policy decision and enforcement points.
XACML is an OASIS standard for writing and evaluating authorisation policy; version 3.0 is the approved version in general use, and a version 4.0 has been published in draft. It provides three things: a policy language for rules over attributes of the subject, the resource, the action and the environment; a request and response format for asking whether one access should be allowed; and a reference architecture that separates the jobs involved. The policy enforcement point intercepts the request, the policy decision point evaluates it, the policy information point supplies attribute values, and the policy administration point manages the policies.
XACML is commonly associated with attribute-based access control, though ABAC does not require it and many implementations use other policy languages. It is distinct from SAML, which chiefly carries statements about authentication and attributes between parties; XACML decides what an authenticated subject may do. The architecture’s value is separation: applications enforce, a central engine decides, and a policy can change without changes to application code.
Exam relevance: questions in this area tend to ask which standard expresses fine-grained authorisation policy, or which component makes the access decision. Candidates are expected to link XACML to ABAC, to keep it apart from SAML’s role in authentication, and to know each policy point by its function.