home/glossary/Role Based Access Control

Role Based Access Control

nounverified·updated May 9, 2026

Role based access control assigns users to roles based on their organizational functions and determines authorization based on those roles.

MWESANS Glossary of Security Terms

Senses

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2

A model for controlling access to resources where permitted actions on resources are identified with roles rather than with individual subject identities.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2sense 2 pending review

Access control based on user roles (i.e., a collection of access authorizations a user receives based on an explicit or implicit assumption of a given role). Role permissions may be inherited through a role hierarchy and typically reflect the permissions needed to perform defined functions within an organization. A given role may apply to a single individual or to several individuals.

Classifications

Entity Type

Control92%rule-basedr:entity.control.safeguard.v1
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

acronym
RBAC
alternatephrasing
Role-Based Access Control
plural
Role Based Access ControlsRole-Based Access Controls
possessive
Role Based Access Control'sRole-Based Access Control's
pluralpossessive
Role Based Access Controls'Role-Based Access Controls'