RBAC Security Assessment Form
Comprehensive assessment of role-based access control security for your organization.
Access-Control Context
*
Which RBAC design model is currently implemented?
*
Flat Role Model
Hierarchical Role Model
Constrained RBAC
Other
How clearly defined is the role hierarchy within your RBAC system?
*
1
2
3
4
5
How frequently are permissions reviewed and updated?
*
Quarterly or more often
Semi-annually
Annually
Rarely or never
Segregation-of-Duties (SoD) Issues
*
Rows
Never
Rarely
Sometimes
Often
Conflicting roles assigned to a user
1
2
3
4
Lack of automated SoD checks
5
6
7
8
Manual overrides without review
9
10
11
12
How are privileged roles (e.g., admin, superuser) managed?
*
Strictly assigned and reviewed
Assigned but not regularly reviewed
Loosely assigned
Not applicable
Describe your provisioning and deprovisioning workflow for user roles.
*
Audit Logging and Review Practices
*
Rows
Not Implemented
Partially Implemented
Fully Implemented
Access attempts are logged
13
14
15
Role changes are logged
16
17
18
Regular review of audit logs
19
20
21
How are exceptions to standard RBAC policies handled?
*
Documented and approved
Ad-hoc, with some documentation
Undocumented exceptions allowed
Exceptions not permitted
Overall, what is the current security risk and priority for improving RBAC in your organization?
*
Low risk / Low priority
1
2
3
4
High risk / High priority
5
1 is Low risk / Low priority, 5 is High risk / High priority
Submit Assessment
Should be Empty: