Role Based Access Control: 6 Proven Rules for a Safer OT

Share:
Cybersecurity
Role Based Access Control: 6 Proven Rules for a Safer OT

In many control rooms one shared password still opens the HMI, the engineering station and the controller download. Giving permissions to roles instead of people keeps operators, engineers and vendors inside their own limits and leaves a clear trail of who changed what.

Least Privilege IEC 62443 FR1 and FR2 No Shared Accounts Audit Trails

Shared logins and full rights for everyone are common in plants and dangerous. Role based access control gives each operator, engineer and vendor only the actions their job needs and records every change.

Hello everyone, today we are going to learn how role based access control works in HMI, DCS and engineering systems, how it links to least privilege and IEC 62443, and how to plan roles in a real plant.
role based access control

What Is Role Based Access Control?

Role based access control is a security method where permissions are attached to job roles, such as operator, shift supervisor or control engineer, and each user receives one or more roles instead of individual rights. In an industrial plant it decides who can view a screen, change a setpoint, bypass an interlock or download logic to a controller in the DCS or PLC.

When a person joins, moves or leaves, the administrator only changes the role assignment. The permissions behind each role stay the same, which makes large systems easier to manage and to audit.

scada-training-security-new-role
Image credit: Ecava IntegraXor. Screenshot courtesy of Ecava IntegraXor, shown here for educational reference.

Most HMI and SCADA packages already include roles, as this IntegraXor screen shows, but plants often leave the defaults untouched. The result is that every console logs in as one powerful user, which defeats the purpose of the feature and weakens SCADA network security.

Do You Know?

NIST SP 800 82 Revision 3, published in September 2023, recommends establishing role based access control with each role configured on the principle of least privilege. It also states that OT network accounts should not use corporate network user accounts.

Advertisement

Users, Roles and Permissions Explained

UserA named person, such as Ravi the shift operator, with a unique login
RoleA job function, such as Operator Area 3, that groups permissions
PermissionAn allowed action on an object, such as write setpoint on unit 300
ObjectA screen, tag, faceplate, controller or engineering function
SessionThe live login where the role permissions are enforced and logged

A user can hold more than one role, for example operator in two process areas. Permissions are never given directly to a user, so an auditor can read the role table and know exactly what every person can do.

In a DCS the objects are spread across the engineering, operator and automation stations. A good design covers all three, not only the operator graphics.

Viewer

Can see graphics, trends and alarms but cannot change anything.

Best for: management, quality and visiting engineers
Read only
Operator

Can start equipment, change setpoints and acknowledge alarms in an assigned area.

Best for: panel operators on shift
Area limited
Supervisor

Operator rights plus alarm shelving, limit changes and selected overrides.

Best for: shift in charge
Elevated
Engineer

Can edit configuration, tune loops and download logic under change control.

Best for: control and instrument engineers
Privileged
Vendor

Time limited access to specific systems through a monitored remote path.

Best for: OEM and service partners
Temporary

Least Privilege and Separation of Duties

Least privilege means each role holds only the permissions needed for its tasks, nothing more. An operator who never tunes loops should not see the PID tuning fields, even if the person is trusted.

Separation of duties splits sensitive work between roles so no single person can complete it alone. A common example is that an engineer makes a logic change offline while a different person approves the download, as covered in PLC online and offline programming.

Quick Tip

Start every new role with no permissions and add rights one by one from the job description. Copying the administrator role and removing items always leaves forgotten privileges behind.

Role Based Access Control in IEC 62443

IEC 62443 organises system security into seven foundational requirements. FR1 covers identification and authentication control, and FR2 covers use control, which is where roles and permissions live, alongside the zones and conduits model.

IEC 62443 ItemWhat It Asks ForPlant Example
FR1 Identification and AuthenticationEvery human user is identified and authenticatedUnique login on each HMI and engineering station
FR2 Use ControlAuthenticated users only get authorised actionsOperator cannot download logic
SR 2.1 Authorization EnforcementThe system enforces permissions on all usersRole table checked on every write
Permission Mapping to RolesRights are grouped by role, not by personOperator, supervisor, engineer roles
FR6 Timely Response to EventsSecurity events are logged and reviewedAudit trail of logins and changes

The standard also describes requirement enhancements such as supervisor override and dual approval for the highest security levels. Dual approval suits actions like bypassing a trip, where two people must agree before the system accepts the command.

Do You Know?

MITRE ATT&CK for ICS lists Authorization Enforcement as mitigation M0800 and says assigning permissions through roles reduces the overhead of managing many devices. It also points to IEC 62351 for power sector roles and IEEE 1686 for IED user permissions.

6 Proven Rules for Role Design in Plants

1
Inventory Systems and Users
List every HMI, server, controller and engineering tool with its current accounts.
2
Define Roles From Job Tasks
Write what each job must do, area by area, before touching the software.
3
Apply Least Privilege
Give each role only the permissions those tasks need.
4
Remove Shared Accounts
Issue a unique named login to every person, including contractors.
5
Integrate With a Directory
Manage OT users centrally in a separate OT domain, not the corporate one.
6
Review and Audit Regularly
Check role membership every quarter and remove leavers at once.

The inventory step is easier when you already maintain an OT asset inventory. Without it, forgotten engineering laptops and old HMI nodes keep their default accounts for years.

CGI warns that default accounts built into operating systems and applications are well known to attackers. They should be disabled or have their privileges reduced as early as possible in a project.

Advertisement

Why Shared Accounts Are So Common and So Risky

Shared accounts appear because shift changes are fast and nobody wants an operator locked out during an upset. The price is that the audit trail shows only OPERATOR1, so nobody can tell who bypassed an interlock at 3 am.

Many HMI platforms solve this with fast user switching, badge readers or a shared station login combined with named action level sign in. The console stays running while each person signs individual changes with their own credentials.

Myth: Plant networks are isolated, so access control is not needed.
Fact: Insiders, contractors and infected laptops all reach the control network from inside.
Myth: Unique logins slow operators during an emergency.
Fact: Fast user switching and a running console keep the response time unchanged.
Myth: Access roles are only a software setting.
Fact: It needs job analysis, joiner and leaver processes and regular reviews.
Myth: Engineers need administrator rights all the time.
Fact: Elevated rights can be requested for a change window and then removed.

Directory Integration and Strong Authentication

Large plants manage users through a directory service, usually a dedicated OT domain controller placed inside the control network or the industrial DMZ. CGI notes that centralised identity and access management lets owners control, audit and revoke access proactively.

For privileged and remote access, CGI recommends multi factor authentication or PKI certificates because passwords are open to brute force, dictionary and phishing attacks. Remote vendor sessions should pass through a monitored gateway, as described in PLC remote access security.

7Foundational requirements in IEC 62443
13ICS techniques mitigated by M0800
2023NIST SP 800 82 Revision 3 issued
1000Supervisor access level in the IntegraXor example

Access Review Effort Formula

A simple way to show management the value of roles is to compare how many grants an auditor must review. Without roles each user can hold any permission directly, while with roles the auditor checks user assignments plus the role definitions.

Direct grants, worst case = U × P
Grants with roles = U × A + R × K

U = users, P = permissions, A = roles per user
R = roles, K = permissions per role

Example:
U = 40, P = 25, A = 1, R = 5, K = 10
Direct = 40 × 25 = 1000
With roles = 40 × 1 + 5 × 10 = 90
Reduction = (1000 minus 90) ÷ 1000 = 91.0 percent

Role Review Calculator

Access Review Workload With and Without Roles
Result
Direct grants 1000, with roles 90, reduction 91.0 percent

The calculator assumes one role per user, which is typical for operators. The real gain is larger in plants with hundreds of users and many process areas.

Second Worked Example: Fertiliser Plant With Three Areas

A plant has ammonia, urea and utilities areas with 10 operators each, 3 supervisors, 6 engineers and 2 vendor accounts. The team creates one operator role per area, one supervisor role, one engineer role and one vendor role, so 6 roles cover 41 people.

When an operator moves from urea to ammonia, the administrator changes one role assignment and the new area permissions follow at once. Vendor accounts stay disabled until a work permit is raised, which supports the incident response plan if a vendor laptop is ever compromised.

Quick Tip

Give supervisors the alarm shelving permission but not operators, so every shelved alarm has a senior owner. This matches the shelving controls in ISA 18.2 described in our guide on alarm shelving.

Read more about those controls in alarm shelving to ISA 18.2, where time limits and authorisation keep shelved alarms from being forgotten.

Audit Trails and Periodic Review

Every login, failed login, setpoint change, bypass and download should be written to a protected audit log with user name and time. Synchronised clocks matter here, and the same events often feed sequence of events records used after a trip.

CGI notes that without regular reviews users accumulate excessive privileges, a problem often called privilege creep. A quarterly review signed by the area manager is a practical habit for Indian plants that face audits from customers and regulators.

Advantages of Role Based Access Control
  • Each person gets only the rights the job needs.
  • Joiners, movers and leavers are handled quickly.
  • Audit trails show named users, not shared logins.
  • Supports IEC 62443 FR1 and FR2 compliance.
Limitations and Challenges
  • Initial job analysis takes real effort.
  • Too many roles become hard to manage.
  • Legacy HMIs may support only a few fixed levels.
  • Emergency access rules must be planned carefully.

Role Based Access Control Implementation Checklist

  • Disable or rename every default vendor and operating system account.
  • Create unique named logins for operators, engineers and contractors.
  • Map each role to areas, screens and engineering functions in writing.
  • Separate OT directory accounts from corporate accounts.
  • Enforce multi factor login for engineering and remote access.
  • Enable audit logging on HMIs, servers and controllers.
  • Review role membership and leavers every quarter.

Pair this checklist with the wider SCADA security checklist and the network layering of the Purdue model. Access control works best when the network also blocks paths that no role should ever use.

Advertisement

NIST Guide to OT Security

PDF
NIST SP 800 82 Revision 3, Guide to Operational Technology Security
National Institute of Standards and Technology, September 2023

Access Control Explained in a Short Video

Role Based Access Control FAQ

What is role based access control in OT?

It is a method where permissions are attached to job roles such as operator, supervisor or engineer. Each user receives roles instead of a long list of individual rights.

In a plant it controls who can change setpoints, shelve alarms or download logic. Every action is then recorded against a named person in the audit trail.

How is least privilege different from roles?

Least privilege is the principle that every user should hold only the rights the job really needs. Roles are the practical tool used to apply that principle across many users.

A badly designed role can still give far too many rights to a person. That is why each role should start empty and grow only from the written job tasks.

Which IEC 62443 requirements cover access control?

Foundational requirement 1 covers identification and authentication of every human user. Foundational requirement 2 covers use control, which includes authorization enforcement and mapping of permissions to roles.

Higher security levels add enhancements such as supervisor override and dual approval of commands. These suit sensitive actions like bypassing a safety trip or forcing an output in the plant.

Why are shared accounts a problem?

A shared login hides who actually performed an action on the HMI or engineering station. After an incident, the log shows only a generic name and the investigation stalls.

Shared passwords also spread to former employees and contractors over time. Unique logins with fast user switching remove the risk without slowing the operators down during an upset.

Should OT users be in the corporate directory?

NIST SP 800 82 states that OT network accounts should not use corporate network user accounts. A separate OT domain limits the damage if the office network is breached.

The OT directory can still follow the same joiner and leaver process as the business side. Human resources changes should trigger account changes in both places on the same day.

How often should roles be reviewed?

A quarterly review of role membership is a practical target for most process plants. Leavers and contractors should be removed on the same day their work at the site ends.

Reviews also catch privilege creep, where people collect extra rights over the years. The area manager should sign each review so that accountability is clear and visible to auditors.

Can old HMIs support role based access control?

Many older HMIs offer only a few numbered security levels instead of real roles. Those levels can still be mapped to operator, supervisor and engineer duties with care.

Where the software is too limited, use compensating controls on the network and the operating system. Plan a proper solution during the next upgrade or migration of the control system.

Advertisement

Related Articles

External References

What We Learn Today

  • Role based access control attaches permissions to job roles such as operator, supervisor and engineer, so each user receives roles instead of individual rights.
  • IEC 62443 places access control under FR1 identification and authentication and FR2 use control, while NIST SP 800 82 recommends roles built on least privilege.
  • Remove shared and default accounts, keep OT users in a separate directory, log every change and review role membership every quarter.
I hope you like above blog. There is no cost associated in sharing the article in your social media. Thanks for reading!! Happy Learning!!
Sunayana Gadepatil, author at Instrumentation Blog
Author · instrumentationblog.in
Ms. Sunayana Gadepatil is an instrumentation professional, technical writer, and the author behind Instrumentation Blog. With a strong interest in industrial instrumentation, process measurement, and automation, she specializes in simplifying complex technical concepts into clear, practical, and easy to understand insights. Through her articles, Ms. Sunayana shares valuable knowledge on flow, pressure, level, temperature, control systems, and industrial automation for engineers, students, technicians, and industry professionals.
Technically reviewed on

Leave a Reply

Your email address will not be published. Required fields are marked *