Glossary · OT cybersecurity
Access control
Also known as: Access management
German: Zugriffskontrolle
In industrial cybersecurity, access control is the set of technical and organizational measures that limit which users, devices and software processes can reach, read, change or operate an asset. It combines authentication (who is this?) with authorization (what may they do?) and records what was done.
- OT security
- Standards
In one sentence
Access control limits who and what can reach, read, change or operate an automation asset, combining authentication, authorization and logging.
Example
On a packaging line, operators can acknowledge alarms on the HMI, while only maintenance engineers with their own accounts can download changed PLC programs.
How it applies
- Engineering: Access control is designed per Security zone and per interface: local HMI accounts, engineering workstation access, Remote access and machine-to-machine connections each need their own rules. IEC 62443-3-3 covers it mainly under the foundational requirements for identification and authentication control and for use control.
- Operation: Shared accounts such as a single "operator" login make it impossible to trace who changed a setpoint. Personal accounts, Role-based access control (RBAC) and Least-privilege access keep actions attributable.
- Maintenance: Access rights must be reviewed when staff, service partners or roles change; forgotten service accounts are a common weakness.
- Documentation: The operating and security documentation should list the roles, what each role may do, how accounts are created and removed, and which default passwords must be changed at commissioning. Keep this consistent with the user management screens described in the operating manual.
Access control vs. authentication
Authentication only establishes identity. Access control is the broader mechanism that also decides and enforces what an authenticated identity is allowed to do, and keeps a record of it.