An organization uses a role-based access control (RBAC) model. After an audit, it was discovered that users have accumulated excessive permissions due to role proliferation. The security architect proposes migrating to an attribute-based access control (ABAC) model. Which challenge is MOST likely to be encountered during this migration?
ABAC's power derives from its ability to make fine-grained access decisions based on a multitude of attributes related to the user, resource, action, and environment. This necessitates a robust and consistent attribute taxonomy, requiring significant upfront effort to define, standardize, collect, and maintain these attributes across various identity stores and systems. The sheer volume, dynamic nature, and precision required for attributes, coupled with their lifecycle management, represent the most substantial initial and ongoing complexity in an ABAC implementation.
Why this answer
Migrating from RBAC to ABAC requires defining a comprehensive set of attributes (subject, resource, environment) and the policies that combine them, which is inherently more complex than managing static role assignments. Role proliferation in RBAC often results from an attempt to mimic attribute-based decisions, but ABAC shifts the complexity from role engineering to attribute governance and policy logic, making attribute definition and management the primary challenge.
Exam trap
The trap here is that candidates confuse the operational challenge of performance (Option B) with the architectural challenge of attribute management, but CISSP emphasizes that the most significant hurdle in ABAC adoption is the complexity of defining and governing attributes, not the runtime evaluation speed.
How to eliminate wrong answers
Option A is wrong because RBAC already involves assigning roles to users, and migrating to ABAC eliminates the need for role assignment entirely, replacing it with attribute-based policy evaluation; difficulty in assigning roles is a pre-existing RBAC problem, not a new challenge of migration. Option B is wrong while ABAC can introduce performance overhead due to real-time policy evaluation, this is typically mitigated by policy caching and optimized engines, and it is not the most likely challenge compared to the fundamental complexity of attribute management. Option C is wrong because lack of support for ABAC in legacy applications is a potential integration issue, but it is not the most likely challenge; many legacy systems can be adapted via a policy enforcement point (PEP) or attribute proxy, whereas the core difficulty lies in defining and maintaining the attribute schema and policies themselves.