Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) is an access control model in which permissions are assigned not to individual users but to roles. Users receive one or more roles according to their function and thus automatically the associated rights.
The model was formalized in the 1990s at the US National Institute of Standards and Technology (NIST) and published as standard ANSI/INCITS 359 in 2004. In addition to simple roles, it provides for role hierarchies, in which superior roles inherit the rights of subordinate ones, as well as constraints such as segregation of duties. RBAC simplifies administration and auditing, because a manageable number of roles is maintained instead of thousands of individual rights. Typical weaknesses are role explosion, i.e. the uncontrolled proliferation of ever more specific roles, and roles that accumulate too many rights over time.
For context-dependent decisions, RBAC is frequently complemented by Attribute-Based Access Control (ABAC), which additionally takes into account characteristics such as device, location or risk. As a model of Access Control widely used in organizations, RBAC forms the basis of many IAM and IGA processes and is an established building block of Identity Security.