RBAC
Role-Based Access Control (RBAC) assigns access rights through roles based on functions within an organisation.
Role-Based Access Control (RBAC) assigns access rights via roles instead of to individuals. A person receives one or more roles, and each role has defined permissions.
How it works
Roles are usually based on functions like 'Accounting', 'HR Officer' or 'Server Administration'. Each role receives the exact rights required for its function. New employees are given the roles for their job. When an employee changes jobs, old roles are removed and new ones assigned. This simplifies administration and makes permissions traceable.
For example, a company has 600 employees and 40 applications. Without roles, thousands of individual permissions would need maintenance. With RBAC, there are 35 roles. An audit can quickly show which people have access to salary data. The list is short and justified.
What to look out for
- Keep the number of roles manageable. Too many special roles devalue the model.
- Regularly review roles for permissions that are no longer needed.
- Watch for incompatible roles, such as creating and approving payments.
- Treat administrator roles with special care, using PAM and time-limited access.
- Automate role assignment through the HR system.
Limitations
RBAC is static. It does not consider context like location, device or time of day. For such conditions, many organisations supplement RBAC with ABAC or Conditional Access. In the cloud, RBAC often leads to many granular roles. These can be difficult to oversee.
Switzerland and regulation
ISO 27001 and FINMA requirements demand traceable assignment and regular reviews of access rights. RBAC simplifies providing this evidence considerably. The revFADP (revised Federal Act on Data Protection) also requires that only authorised persons can access personal data.
Typical mistakes
People often accumulate roles over many years without old ones being removed. A second mistake is creating roles that are defined too broadly for convenience.
Relevance for the SOC
The SOC monitors changes to critical roles, such as additions to admin groups. Such changes are common steps in attacks.
How we implement it
We monitor changes to privileged roles in your directories and cloud environments. We are happy to discuss architecture questions as part of our Security Consulting.