Role-Based Access Control
What is Role-Based Access Control?
An access management approach that assigns permissions to defined roles rather than individual users, simplifying administration and enforcing least privilege.
Terms that appear alongside role-based access control
Each of these is named in at least one of the same controls as role-based access control. The number is how many controls name both.
- access control 24 shared controls
- authentication 16 shared controls
- role based access control rbac 13 shared controls
- access management 13 shared controls
- least privilege 13 shared controls
- privileged access management 12 shared controls
- nist 11 shared controls
- multi factor authentication 10 shared controls
Frameworks that govern role-based access control
What the standards actually require on role-based access control
Requirements naming role-based access control across 6 standards, quoted from the control text.
Access control of users and automated agents to data objects in power systems based on roles
62351-8 · Role-based access control (RBAC) →Role-based access controls are implemented for artificial intelligence applications to restrict access to sensitive data.
ISM-2093 · Role-based access controls are implemented for artificial intelligence applications to res →Define and maintain role-based access control, through determining and documenting the access rights necessary for each role within the enterprise to successfully carry out its assigned duties.
CIS-6.8 · Define and Maintain Role-Based Access Control →Security Dimension 1 Access Control per X.805 Clause 6.1: Access Control protects against unauthorized use of network resources. Access Control ensures that only authorized personnel or devices are allowed access to network elements + stored information + info...
X805-Dim1-Access-Control-RBAC-Authorization-Resources-Network-Elements-Services-Applications · ITU-T X.805 Security Dimension 1 - Access Control + Role-Based Access Control (RBAC) + Authorization + Resources + Network Elements + Services + Applications + Access Limitations + Authorized Personnel + Discretionary + Mandatory Access Control →Apply just enough administration by managing permissions at fine granularity, using role-based access control to grant only the access a role needs.
ASBv3-PA-7 · Follow just enough administration (least privilege) principle →Section 11.10 access + control elements: (d) LIMITING SYSTEM ACCESS TO AUTHORISED INDIVIDUALS - role-based access control (RBAC) + least-privilege + provisioning + de-provisioning lifecycle + periodic access reviews + segregation of duties;
Part11.AccessAndAuth · Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h)) →Questions people ask about role-based access control
What is Role-Based Access Control?
Why is Role-Based Access Control important for compliance?
Which compliance frameworks address Role-Based Access Control?
Where can I learn more about Role-Based Access Control?
See how Role-Based Access Control applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.