Term · 14. International Standards
NIST RBAC
Definition
NIST RBAC Standard — INCITS 359-2012 (Role-Based Access Control). Defines four RBAC variants: Flat RBAC (basic roles+users), Hierarchical RBAC (role inheritance), Constrained RBAC (SoD policies), Symmetric RBAC (review queries). De-facto international standard for RBAC implementations.
- Synonyms
-
- NIST RBAC (INCITS 359)
- Application
- Foundation for most enterprise IAM RBAC implementations. Referenced in NIST SP 800-53, NIST SP 800-162 (ABAC). Modern IGA platforms (SailPoint, Saviynt, Microsoft Entra) implement Constrained RBAC + Hierarchical RBAC variants.
- Standards & regulations
-
- INCITS 359-2012 «This standard consists of two main parts the RBAC Reference Model and the RBAC System and Administrative Functional Specification. The RBAC Reference Model defines sets of basic RBAC elements (i.e., u»
- ANSI/INCITS 359-2004 «The NIST model for RBAC was adopted as American National Standard 359-2004 by the American National Standards Institute, International Committee for Information Technology Standards (ANSI/INCITS) on F»
- Sources
-
- NIST RBAC — INCITS 359-2012 / NIST publications primary source
Related terms
-
Access Object
Access Object — a unit of an information resource for which access is regulated by access control rules. May be a file, …
-
Access Subject
Access Subject — a person or process whose actions are regulated by access control rules to information system objects. …
-
Forrester Zero Trust (originator framework) (ZTX)
Originated by Forrester analyst John Kindervag in 2010 as «No more chewy centers — abolish the trusted network», Zero Tr …
-
Access Control (AC)
Mechanism that determines whether a principal is permitted to perform a specific action on a specific resource. Includes …
-
Access Management (AM)
Discipline of granting and enforcing access to resources after identity has been established. Encompasses authentication …
-
Attribute-Based Access Control (ABAC)
Authorization model evaluating attributes of subject (role, department, clearance), object (sensitivity, owner), action …