Secure Controls Framework

1,534 controls across 34 domains

Source: SCF 2026.2About SCF
securecontrolsframework.com
Back to catalog
IAC-08IACIdentification & Authentication

Role-Based Access Control (RBAC)

Description

Mechanisms exist to enforce Role-Based Access Control (RBAC) for Technology Assets, Applications, Services and/or Data (TAASD) to restrict access to individuals assigned specific roles with legitimate business needs.

Cross-Mappings

56 paths across 3 frameworks
NIST 800-531 mapping
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI6 mappings
CCI-001358
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001360
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001407
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002136
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002137
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003630
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
STIG40 mappings
SV-104483r1_ruleSymantec ProxySG must be configured with only one local account that is used as the account of last resort.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V1R2 · disa_xccdf · related
SV-202051r1051115_ruleThe network device must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V5R3 · disa_xccdf · related
SV-215679r1051115_ruleThe Cisco router must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-215824r1051115_ruleThe Cisco router must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-216530r1051115_ruleThe Cisco router must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-217321r1051115_ruleThe Juniper router must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V3R2 · disa_xccdf · related
SV-220487r1051115_ruleThe Cisco switch must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-220487r960969_ruleThe Cisco switch must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V3R2 · disa_xccdf · related
SV-220535r1051115_ruleThe Cisco switch must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-220587r1051115_ruleThe Cisco switch must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related

+30 more (top 10 by confidence shown)

Control mappings provided by the Secure Controls Framework (SCF).

SCF

Powered by the Secure Controls Framework

The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.

© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer