Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Access control

Also known as: Access management

German: Zugriffskontrolle

In industrial cybersecurity, access control is the set of technical and organizational measures that limit which users, devices and software processes can reach, read, change or operate an asset. It combines authentication (who is this?) with authorization (what may they do?) and records what was done.

  • OT security
  • Standards

In one sentence

Access control limits who and what can reach, read, change or operate an automation asset, combining authentication, authorization and logging.

Example

On a packaging line, operators can acknowledge alarms on the HMI, while only maintenance engineers with their own accounts can download changed PLC programs.

How it applies

  • Engineering: Access control is designed per Security zone and per interface: local HMI accounts, engineering workstation access, Remote access and machine-to-machine connections each need their own rules. IEC 62443-3-3 covers it mainly under the foundational requirements for identification and authentication control and for use control.
  • Operation: Shared accounts such as a single "operator" login make it impossible to trace who changed a setpoint. Personal accounts, Role-based access control (RBAC) and Least-privilege access keep actions attributable.
  • Maintenance: Access rights must be reviewed when staff, service partners or roles change; forgotten service accounts are a common weakness.
  • Documentation: The operating and security documentation should list the roles, what each role may do, how accounts are created and removed, and which default passwords must be changed at commissioning. Keep this consistent with the user management screens described in the operating manual.

Access control vs. authentication

Authentication only establishes identity. Access control is the broader mechanism that also decides and enforces what an authenticated identity is allowed to do, and keeps a record of it.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: IEC 62443-3-3:2013, Industrial communication networks — Network and system security — Part 3-3: System security requirements and security levels

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!