Role-Based Access Control Assessment Form
Assess your organization’s current role-based access control structure, governance, and improvement priorities.
RBAC Scope and Environment
Organization or Department Name
*
System/Application Name(s) in Scope
*
Environment or Access Domain Being Assessed
*
Production
Staging
Development
Internal Tools
Customer-Facing Applications
Data Warehouse / Analytics
Other
Notes on Included / Excluded Access Domains
Roles, Permissions, and Governance
Current Roles Inventory
*
How well do roles match job functions?
*
Poorly aligned
1
2
3
4
Fully aligned
5
1 is Poorly aligned, 5 is Fully aligned
How clear are role ownership and approval responsibilities?
*
Very unclear
1
2
3
4
Very clear
5
1 is Very unclear, 5 is Very clear
How consistently is least-privilege applied?
*
Rarely applied
1
2
3
4
Always applied
5
1 is Rarely applied, 5 is Always applied
How are user access requests provisioned and removed?
*
Please Select
Fully automated via workflow
Semi-automated with manager or approver review
Manually processed by IT or administrators
Decentralized by team or department owners
Ad hoc and inconsistent
Other
How frequently are access reviews performed?
*
1
2
3
4
5
Risks, Pain Points, and Priorities
Current RBAC pain points
*
Role sprawl
Excessive permissions
Manual approvals
Slow onboarding/offboarding
Unclear ownership
Exception handling
Audit difficulty
Inconsistent role definitions
Other
Most critical issue
*
Role sprawl
Excessive permissions
Manual approvals
Slow onboarding/offboarding
Unclear ownership
Exception handling
Audit difficulty
Inconsistent role definitions
Other
Top priority improvement(s)
*
Additional comments or constraints
Submit Assessment
Should be Empty: