home/dictionary/Role Based Access Control

Role Based Access Control

nouncandidate·updated May 9, 2026

Role based access control assigns users to roles based on their organizational functions and determines authorization based on those roles.

Framework senses

SANS Glossary of Security Terms1 senseview framework →
§1
Role based access control assigns users to roles based on their organizational functions and determines authorization based on those roles.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
A model for controlling access to resources where permitted actions on resources are identified with roles rather than with individual subject identities.
§2 · sense_2_pending_review
Access control based on user roles (i.e., a collection of access authorizations a user receives based on an explicit or implicit assumption of a given role). Role permissions may be inherited through a role hierarchy and typically reflect the permissions needed to perform defined functions within an organization. A given role may apply to a single individual or to several individuals.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
Access control based on user roles (i.e., a collection of access authorizations a user receives based on an explicit or implicit assumption of a given role). Role permissions may be inherited through a role hierarchy and typically reflect the permissions needed to perform defined functions within an organization. A given role may apply to a single individual or to several individuals.
NIST SP 800-531 senseview framework →
§1
Access control based on user roles (i.e., a collection of access authorizations a user receives based on an explicit or implicit assumption of a given role). Role permissions may be inherited through a role hierarchy and typically reflect the permissions needed to perform defined functions within an organization. A given role may apply to a single individual or to several individuals.
NIST SP 800-951 senseview framework →
§1
A model for controlling access to resources where permitted actions on resources are identified with roles rather than with individual subject identities.