Role-based access control is a security strategy that limits access to computer systems and data based on individuals' roles or job functions within an organization. It ensures that individuals only have access to the information and resources necessary for them to perform their job duties, and nothing more. This approach minimizes the potential for unauthorized access to sensitive data by limiting access privileges to only what is required for an individual's specific role.