RBAC, ABAC and least privilege: a short lesson
ILM Reference editors · Published 2026-02-10 · 2 minute read
TRACK: CONTROLS AND STANDARDS · LESSON 5 OF 11
Role-based access control gives people access by assigning them roles; attribute-based access control decides access by evaluating attributes against policy at the time of the request. Least privilege is the principle both serve: access limited to what a person or process needs for its task. Most programs use roles for birthright access and attributes or requests for the rest.
What is RBAC?
NIST's glossary describes role-based access control as a model where permitted actions on resources are identified with roles rather than with individual subject identities. In lifecycle terms, a joiner receives the roles for their job, a mover swaps roles, and a leaver loses them. The weakness is role sprawl: roles multiply, and movers keep old roles when nobody removes them.
What is ABAC?
NIST SP 800-162 defines attribute-based access control as a method where authorization to perform operations is decided by evaluating attributes of the subject, the object, the requested operation and, in some cases, the environment against policy. Because access follows attributes such as department or location, a mover whose HR attributes change can lose old access without anyone editing a role. The weakness is that the result is only as good as the attribute data.
Where does least privilege fit?
Least privilege is the principle that users, and processes acting for them, get only the access needed for their assigned tasks. RBAC and ABAC are ways to implement it; access reviews check whether it held. Local accounts in disconnected applications sit outside both models, which is why they drift from least privilege first.
Sources
Reviewed Sep 2026
Next lesson: DORA access requirements
The two articles that turn DORA into joiner, mover, leaver and review requirements.