Glossary · OT cybersecurity
Role-based access control (RBAC)
Also known as: RBAC, Role-based access
German: Rollenbasierte Zugriffskontrolle (RBAC)
In access control, role-based access control (RBAC) is a model in which permissions are assigned to roles, such as operator, maintenance technician or engineer, and users receive permissions only by being assigned to one or more roles.
- OT security
In one sentence
Role-based access control (RBAC) assigns permissions to roles such as operator or engineer, and users get permissions only through their roles.
Example
On the HMI, the role "Operator" can start and stop the line, "Maintenance" can also jog axes in setup mode, and "Engineer" can change machine parameters.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
How it applies
- Engineering: Roles are derived from real tasks. Too few roles force over-privileged accounts; too many make administration error-prone. Central user management, for example through a directory service, keeps roles consistent across HMIs, SCADA and engineering tools.
- Operation: When staff change jobs, only their role assignment changes. This makes access reviews and removal of rights manageable.
- Safety: Roles are often linked to operating modes: changing to a special mode such as setup may require a role with the appropriate training. The role check is a security and organizational measure and does not replace the safety functions of the mode itself.
- Documentation: Operating manuals should list the roles, the tasks and screens each role can access, and the qualifications required. Task topics can state the required role in their prerequisites.
RBAC vs. least privilege
RBAC is a mechanism. Least-privilege access is a goal: RBAC helps achieve it only when roles are designed narrowly.