Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Role-based access control (RBAC)

Also known as: RBAC, Role-based access

German: Rollenbasierte Zugriffskontrolle (RBAC)

In access control, role-based access control (RBAC) is a model in which permissions are assigned to roles, such as operator, maintenance technician or engineer, and users receive permissions only by being assigned to one or more roles.

  • OT security

In one sentence

Role-based access control (RBAC) assigns permissions to roles such as operator or engineer, and users get permissions only through their roles.

Example

On the HMI, the role "Operator" can start and stop the line, "Maintenance" can also jog axes in setup mode, and "Engineer" can change machine parameters.

Explained in context

Context cards connect this term with others to answer one question. Also in British English and German.

How it applies

  • Engineering: Roles are derived from real tasks. Too few roles force over-privileged accounts; too many make administration error-prone. Central user management, for example through a directory service, keeps roles consistent across HMIs, SCADA and engineering tools.
  • Operation: When staff change jobs, only their role assignment changes. This makes access reviews and removal of rights manageable.
  • Safety: Roles are often linked to operating modes: changing to a special mode such as setup may require a role with the appropriate training. The role check is a security and organizational measure and does not replace the safety functions of the mode itself.
  • Documentation: Operating manuals should list the roles, the tasks and screens each role can access, and the qualifications required. Task topics can state the required role in their prerequisites.

RBAC vs. least privilege

RBAC is a mechanism. Least-privilege access is a goal: RBAC helps achieve it only when roles are designed narrowly.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: ANSI/INCITS 359, Information Technology — Role Based Access Control

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!