Slide 12
Slide 12 text
Why NGAC?
● Policy modeling capabilities
● Ease of Administration
● Decision-time Performance
● Policy Review
○ Audit (incl. “before the fact”): see what resources are (will be) affected by a policy
○ Explain: understand why a particular access was allowed, in human-readable terms;
eg:
■ “Nic was allowed access because:
● He is a member of group A which has RBAC policy B (authored by Zack on
Sep 1, 2021) granting permissions X,Y,Z on container C, which contains the
target resource Foo
● He is a member of group F which was granted a location based policy G
(authored by Varun on August 27, 2021) which grants permission X on
container H, which contains the target resource Foo
● Only location and RBAC policies applied, therefore Nic is able to take
action X on target resource Foo.”