The process of allowing or restricting permissions of data and networks. Goal is to conform to Principle of Least Privilege. Tools ACL Whitelist Blacklist Concepts Mandatory Access Control Discretionary Access Control Role-Based Access Control Attribute Based Access Control Rule-Based Access Control