Join our Newsletter — 33% off our NHI Course
Foundations & NHI Taxonomy

GAP

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Foundations & NHI Taxonomy

The Generic Access Profile defines how BLE devices discover one another and establish interaction rules. It covers visibility, such as scanning and advertising, and connection behavior, including roles, modes, and security parameters. GAP sets the conditions that make later data exchange possible.

What GAP does in Bluetooth Low Energy

GAP, the Generic Access Profile, is the Bluetooth Low Energy layer that governs how devices become visible to one another, advertise themselves, and decide whether interaction can begin. It establishes the conditions needed before any higher-level service exchange can happen.

At a practical level, GAP is about discovery and connection behavior. It defines how devices scan, advertise, choose roles, and negotiate the basic parameters that shape a later connection, including security-related settings that influence whether the link can be trusted.

Where GAP sits in the BLE stack

GAP is not the application layer and it is not the data protocol that carries business information. Instead, it sits earlier in the BLE lifecycle, making the device discoverable and setting the relationship rules that let two endpoints move from “present” to “connected.”

That placement matters because many later outcomes depend on the setup choices made here. If visibility, role selection, or connection mode is weakly designed, the rest of the BLE interaction starts from a fragile base even if later payload handling is well protected.

Core functions covered by GAP

GAP covers the basic interaction model for BLE peers. It defines advertising and scanning behavior, connection establishment, peripheral and central roles, and the operating modes a device can use when it is trying to be found or trying to find others.

It also influences how a device presents itself to the surrounding environment. In BLE, that presentation is not just cosmetic, because discoverability, timing, and connection parameters can affect usability, interoperability, and the exposure surface created by the radio interface.

  • Discovery, through advertising and scanning
  • Connection setup, including when and how a link is formed
  • Role behavior, such as central and peripheral responsibilities
  • Basic security parameter negotiation that supports later protected communication

Why GAP matters for security and reliability

Because GAP controls the entry point to BLE interaction, it strongly influences who can attempt a connection and under what conditions. A device that advertises too broadly, stays discoverable too long, or accepts weak connection assumptions creates a wider opportunity for unintended interaction.

At the same time, GAP is only the starting point. It does not by itself guarantee confidentiality or authentication for all later traffic, but it helps establish whether the subsequent link has a reasonable security posture from the outset.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-3 — Device Identification and AuthenticationBLE device discovery and link setup depend on authenticating the device endpoint.
IA-5 — Authenticator ManagementGAP security parameters rely on managed credentials and authentication material.
AC-17 — Remote AccessBLE discovery and connection creation establish a remote communication path to a device.
Recommendation — Apply IA-3 to authenticate BLE devices before allowing trusted link establishment. Apply IA-5 to protect and rotate the credentials that underpin BLE pairing and access. Apply AC-17 to restrict and control BLE remote access paths and connection behavior.
CIS Controls v8CIS-6 — Access Control ManagementGAP governs which devices can discover and connect, which is an access control question.
Recommendation — Use CIS-6 to limit which BLE devices may be discoverable or allowed to connect.
ISO/IEC 27001:2022A.8.20 — Network SecurityBLE GAP shapes the conditions for network-style wireless connectivity and exposure.
Recommendation — Use A.8.20 to secure BLE connectivity settings and limit unnecessary exposure.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org