Groups and roles

Two ways of administering access in bulk: a group collects accounts so permissions can be granted together, while a role is a set of permissions defined by a job function.

Groups and roles let access be managed in bulk, and the ISC2 exam outline lists them together under objective 5.2. A group is a collection of accounts: a permission granted to the group reaches every member. A role is a set of permissions defined by what a job function needs, and it is the unit of role-based access control. Many systems implement a role as a group, which is why the two words are often confused. The difference is what defines each: a role is defined by the duties of the job, a group by who is in it.

Because membership carries permissions, adding someone to a group or role is a privilege decision. NIST SP 800-53 Rev. 5 control AC-2 asks organisations to set prerequisites and criteria for group and role membership and to specify membership for each account. A role should be defined from the job before anyone is placed in it, not copied from a current holder, whose privilege creep would be copied too. Membership is then checked in access review.

Exam relevance: a scenario is likely to describe access granted by copying another user’s permissions and ask for the better practice. Candidates are expected to prefer roles defined from job duties, in support of least privilege, and to treat membership changes as access decisions.