Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

RBAC – Is it implemented in your organization?

By Sean Lawless on December 23, 2015
Email this postTweet this postLike this postShare this post on LinkedIn

Traditionally it was very common for organizations to adopt an optimistic security model. Give everyone access to everything unless specifically denied access to sensitive areas, like HR or Finance. While this approach is generally regarded as more convenient for end users, it is less secure and leaves organizations more vulnerable than pessimistic security models. Pessimistic security models generally deny access to everything for everyone unless specifically granted access. While more secure, the pessimistic model tends to hamper collaboration and can be tedious to maintain properly. Early security models were very static and assigned permissions to individual users for individual systems or tasks. In large organizations such models become extremely difficult to administer.

Formalized in 1992 by David Ferraiolo and Rick Kuhn, Role Based Access Control (RBAC) has become one of the most widely used security models. RBAC grants access to systems or the ability to perform tasks based on roles. Roles are determined by job function, job responsibilities, job competency, authority within the organization, etc. There are essentially only three primary rules in an RBAC system.

  1. Role Assignment: users can only perform function(s) if they have been assigned a role.
  2. Role Authorization: users must be authorized for the role to which they are assigned.
  3. Permission Authorization: the specific function or permission must be authorized to the role.

Implementing an RBAC security model allows for more dynamic provisioning of security permissions while maintaining a high level of accountability and auditability. Users receive the rights and access necessary based on their assigned role without having to configure each individual system. RBAC can even be used to automate many business processes providing more efficiencies to your environment.

For more detailed and technical information on RBAC visit the recommended sites listed below.

National Institute of Standards and Technology

Ferraiolo and Kuhn’s 1992 White Paper

Photo of Sean Lawless Sean Lawless

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries…

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries, develop and implement practical information security programs based on industry standard frameworks. Sean holds a Bachelor of Science degree from the University of Connecticut and is a member of several cybersecurity professional organizations.

Read more about Sean LawlessEmail
Show more Show less
  • Posted in:
    Corporate Governance and Compliance, Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo