Role-Based Access Control (RBAC)
What is Role-Based Access Control (RBAC)?
An access control method that assigns permissions to users based on their role within an organisation rather than their individual identity. RBAC simplifies access management by grouping permissions into roles aligned with job functions.
Terms that appear alongside role-based access control (rbac)
Each of these is named in at least one of the same controls as role-based access control (rbac). The number is how many controls name both.
- role based access control 13 shared controls
- access control 13 shared controls
- authentication 10 shared controls
- privileged access management 9 shared controls
- access management 9 shared controls
- privileged access management pam 8 shared controls
- nist 8 shared controls
- least privilege 8 shared controls
Frameworks that govern role-based access control (rbac)
What the standards actually require on role-based access control (rbac)
Requirements naming role-based access control (rbac) across 6 standards, quoted from the control text.
Access control of users and automated agents to data objects in power systems based on roles
62351-8 · Role-based access control (RBAC) →Security Dimension 1 Access Control per X.805 Clause 6.1: Access Control protects against unauthorized use of network resources. Access Control ensures that only authorized personnel or devices are allowed access to network elements + stored information + info...
X805-Dim1-Access-Control-RBAC-Authorization-Resources-Network-Elements-Services-Applications · ITU-T X.805 Security Dimension 1 - Access Control + Role-Based Access Control (RBAC) + Authorization + Resources + Network Elements + Services + Applications + Access Limitations + Authorized Personnel + Discretionary + Mandatory Access Control →Section 11.10 access + control elements: (d) LIMITING SYSTEM ACCESS TO AUTHORISED INDIVIDUALS - role-based access control (RBAC) + least-privilege + provisioning + de-provisioning lifecycle + periodic access reviews + segregation of duties;
Part11.AccessAndAuth · Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h)) →UR E26 Goal 2 (Protect) requires access control + authentication + authorization mechanisms for all CBS. Unique user identification (no shared accounts where feasible); strong password policy (per NIST SP 800-63B + IEC 62443 + ship operational reality);
IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles · IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management →NSS-17 + NSS-42-G require comprehensive access control aligned with CSL: unique user identification + no shared accounts where feasible (emergency shared accounts logged + reviewed);
IAEA-NSS17-AccessControl-OT-IT-Authentication-Authorization · IAEA NSS-17 - Access Control + Authentication + Authorization + IAM + Privileged Access for OT and IT →The Privacy Protection (Data Security) Regulations 5777-2017 (Takhanot Hagannat Hapratiyot - Avtahat Meidah) supplement the 1981 Law with detailed technical and organisational security requirements + graduated by Security Level Classification (Basic/Medium/Hig...
IsraelPPL-DataSecurity-Regulations2017-ISO-CISO-Access-Logging-Backup-Physical-Removable-Annual-Audit · Israel POPL Data Security Regulations 5777-2017 + ISO Information Security Officer + Access Control + Logging + Backup + Physical Security + Removable Media + Risk Assessment + Penetration Testing + Annual Internal Audit + Amendment 13 Cyber Updates →Questions people ask about role-based access control (rbac)
What is Role-Based Access Control (RBAC)?
Why is Role-Based Access Control (RBAC) important for compliance?
Which compliance frameworks address Role-Based Access Control (RBAC)?
Where can I learn more about Role-Based Access Control (RBAC)?
See how Role-Based Access Control (RBAC) applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.