Virtualization environments offer interesting advantages for Industrial Control Systems (ICS), including being a tool to manage cybersecurity of such systems and a backup tool to control or optimize system behavior. Nevertheless, such virtual environments will likely be shared by different parties that have different access control requirements. In this paper, we discuss architecture and capabilities of virtualized ICS, and provide an analysis of an access control framework for ICS systems. We also present a language to define access control policies for virtualized ICS and developed an open source proof of concept implemented in Open Stack.