The Inner Circle

 View Only

NIST Internal Report (IR) 8504, Access Control on NoSQL Databases, for comment

  • 1.  NIST Internal Report (IR) 8504, Access Control on NoSQL Databases, for comment

    Posted Feb 01, 2024 02:25:00 AM
      |   view attached

    Hi All,

    NIST Invites Public Comments on IR 8504, Access Control on NoSQL Databases

    The initial public draft of NIST Internal Report (IR) 8504, Access Control on NoSQL Databases, is now available for public comment. NoSQL (i.e., "not only SQL" or "non-SQL") database systems and data stores often outperform traditional relational database management systems (RDBMSs) in various aspects, such as data analysis efficiency, system performance, ease of deployment, flexibility/scalability of data management, and users' availability. However, with an increasing number of people storing sensitive data in NoSQL databases, access control issues have become a fundamental data protection requirement for database management systems.
    This document discusses access control on NoSQL database systems by illustrating the NoSQL database types and their support for access control models. It operates under the assumption that the access control system stores and manages access control data (e.g., subjects, objects, and attributes) in the NoSQL database and describes considerations from the perspective of access control in general.

    A public comment period is open through March 15, 2024. See the publication details https://csrc.nist.gov/pubs/ir/8504/ipd for a copy of the draft and instructions for submitting comments. https://csrc.nist.gov/pubs/ir/8504/ipd



    ------------------------------
    Michael Roza CPA, CISA, CIA, CC, MBA, Exec MBA, CSA Research Fe
    ------------------------------