0 / 4
NIST RBAC Levels
Role-based access control (RBAC) assigns permissions to roles and users to those roles, so that users get their permissions through roles. When people change, you move the role rather than fixing permissions one by one. A paper NIST published in 2000 divides RBAC into four levels. The simplest level, Flat, is the base, and each level above it adds one new requirement.
Example: staff at a bank branch getting permissions through roles, starting from Flat with one new requirement added at each step.
1 / 4
Flat RBAC
Users are assigned to roles, and permissions are assigned to roles too. A user gets permissions through roles. Both assignments are many-to-many, so one staff member can take several roles and use their permissions together, and one permission can belong to several roles. In the figure, Staff A has two roles and the customer view permission belongs to two roles. A system must be able to look up the roles a user holds and also the users who hold a role.
2 / 4
Hierarchical RBAC
Roles are placed above and below each other. The branch manager is a senior role to the teller. This relationship, where a senior role gains the permissions of a junior one, is commonly called inheritance, and under inheritance the manager can use the deposit entry permission without being assigned it separately. But whether it works as inheritance, or the senior role has to switch the junior role on itself, is not fixed by the NIST model. A hierarchy that only has to avoid cycles is a general hierarchy, and one limited to simple shapes such as a tree is a limited hierarchy; NIST accepts both.
3 / 4
Constrained RBAC
Splitting a task so that no single person can do all of it is called separation of duty (SOD). If one person handles both loan intake and loan approval, they can commit fraud alone. So the loan officer and branch manager roles cannot be held by the same person. Assigning the manager role to Staff A, who is a loan officer, is refused. Blocking at assignment time is the static way; allowing both roles to be assigned but blocking them from being switched on at the same time during a work session is the dynamic way. The NIST model does not say which to use, and the figure shows the static way.
4 / 4
Symmetric RBAC
Lookup between users and roles was already required at level 1. This level also requires lookup between roles and permissions. A system must be able to find the roles that hold the customer view permission, and the permissions a role holds. Performance should be similar to user-side lookup, but that is hard to build in large distributed systems, so this level comes last.
Note: the paper’s appendix also says that treating Constrained and Symmetric as independent, unordered features is preferable. The 2004 ANSI standard drops levels for four independent components: Core, Hierarchical, SSD (static separation of duty) and DSD (dynamic separation of duty). Only Core is required, and lookup by permission is an optional Core feature. RBAC0–3 is yet another classification.