On September 18, 2017 this (legacy) site will be replaced with the new site you can see at beta.csrc.nist.rip. At that time, links to this legacy site will be automatically redirected to apporpriate links on the new site.
This ACPT version is a beta release, which includes a concise user manual, examples, and java code. Further modification on the user documentation and software are expected. Please check the web site for update information. To download the latest ACPT version (.zip file, October 28, 2015), the source code is also available, please contact: Vincent Hu vhu@nist.gov for password to unzip the zip file.
The Access Control Policy Tool (ACPT) is developed by NIST Computer Security Division in corporation of North Carolina State University and University of Arkansas. The ACPT is provided free of charge and will remain free in the future as long as NIST/ACPT is mentioned, or the ACPT URL are provided in your product. NIST is not responsible for any damage caused by using ACPT.
NIST SBIR awardee InfoBeyond Technology developed Security Policy Tool (SPT) incorporates and enhances the ACPT functions to an access control policy software tool for policy composition, policy verification, policy analysis, and XACML policy export. SPT has rich policy analysis functions such that the policy author can use them to user-friendly analyze if there are access control leaks and then fix these leaks caused by unintended or faulty security policies. It offers Subject/Resource Privilege Access Preview functions to find unintended accessibility, such as: (i) who has the accessibility for a giving resource, and (ii) what resource can access for a given subject. All these functions help a policy author to identify and correct AC flaws, such as block privilege, leak privilege, unprotected objects, Separation of Duty error, etc.
NIST SBIR awardee ObjectSecurity developed and markets the policy testing tool OpenPMF Security Policy Auditor (OpenPMF Auditor™), which is based on ACPT and is embedded into the OpenPMF security policy automation platform. OpenPMF Auditor analyzes information about user’s technical security policies and IT environments; it imports information about user’s IT landscape to automatically generate detailed reports and analytics. OpenPMF Auditor enables manageable, easy-to-use, advanced access control policy testing, which detects potential errors, mistakes and vulnerabilities in access control policies by importing, authoring, analyzing, testing and exporting security policy rules.
User Feedback:
Users have been very positive, and are applying ACPT to a wide variety of software.