Capability-based Security
By Mark Sharron
•
14 December 2020
What is capability-based security?
Capability-based security refers to the design concept in computing systems where an unforgeable token is generated. This token represents the reference to an object, that includes a set of access rights to a computer system.
Using this added layer of security helps to minimise the risk of a successful cyber attack.

Mark Sharron
Mark Sharron leads Search & Generative AI Strategy at ISMS.online. His focus is communicating how ISO 27001, ISO 42001 and SOC 2 work in practice - tying risk to controls, policies and evidence with audit-ready traceability. Mark partners with product and customer teams so this logic is embedded in workflows and web content - helping organisations understand, prove security, privacy and AI governance with confidence.
Read more from Mark Sharron