home/glossary/Role Based Access Control

Role Based Access Control

nounid 3951·updated May 9, 2026
candidate

Role based access control assigns users to roles based on their organizational functions and determines authorization based on those roles.

MWE

Classifications

Entity Type

Control92%rule-basedr:entity.control.safeguard.v1

Sensitivity

unclassified

Information Class

unclassified

Variants

acronym
RBAC
alternatephrasing
Role-Based Access Control
plural
Role Based Access ControlsRole-Based Access Controls
possessive
Role Based Access Control'sRole-Based Access Control's
pluralpossessive
Role Based Access Controls'Role-Based Access Controls'

Framework definitions

SANS Glossary of Security Terms1 senseview framework →
§1
Role based access control assigns users to roles based on their organizational functions and determines authorization based on those roles.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
A model for controlling access to resources where permitted actions on resources are identified with roles rather than with individual subject identities.
§2 · sense_2_pending_review
Access control based on user roles (i.e., a collection of access authorizations a user receives based on an explicit or implicit assumption of a given role). Role permissions may be inherited through a role hierarchy and typically reflect the permissions needed to perform defined functions within an organization. A given role may apply to a single individual or to several individuals.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
Access control based on user roles (i.e., a collection of access authorizations a user receives based on an explicit or implicit assumption of a given role). Role permissions may be inherited through a role hierarchy and typically reflect the permissions needed to perform defined functions within an organization. A given role may apply to a single individual or to several individuals.
NIST SP 800-531 senseview framework →
§1
Access control based on user roles (i.e., a collection of access authorizations a user receives based on an explicit or implicit assumption of a given role). Role permissions may be inherited through a role hierarchy and typically reflect the permissions needed to perform defined functions within an organization. A given role may apply to a single individual or to several individuals.
NIST SP 800-951 senseview framework →
§1
A model for controlling access to resources where permitted actions on resources are identified with roles rather than with individual subject identities.

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.