IAC-08—Role-Based Access Control (RBAC)
Weight: 9
>Control Description
Mechanisms exist to enforce Role-Based Access Control (RBAC) for Technology Assets, Applications, Services and/or Data (TAASD) to restrict access to individuals assigned specific roles with legitimate business needs.
>Cross-Framework Mappings
PCI DSS v4.0.1
CMMC v2.0
Canada ITSP 10.171
New Zealand HISF
Spain ENS
SOC 2 TSC (Detailed)
NIST SP 800-171 Rev 3
NIST SP 800-171A Rev 3
NIST SP 800-207 Zero Trust
45 CFR 155.260
CMMC 2.0 Level 1
GLBA (16 CFR 314)
HIPAA Simplification 2013
NERC CIP
NY DFS 23 NYCRR 500
Ask AI
Configure your API key to use AI features.