graphgrc

SCF - IAC-08 - Role-Based Access Control (RBAC)

Mechanisms exist to enforce a Role-Based Access Control (RBAC) policy over users and resources that applies need-to-know and fine-grained access control for sensitive/regulated data access.

Mapped framework controls

ISO 27002

SOC 2

Control questions

Does the organization enforce a Role-Based Access Control (RBAC) policy over users and resources that applies need-to-know and fine-grained access control for sensitive/regulated data access?