home/dictionary/administrative privilege

administrative privilege

nounverified·updated Aug 30, 2026

A class of access rights — elevated above those granted to standard users — that collectively authorize an account or identity to perform security-sensitive operations that affect the configuration, integrity, or management of a system or network. What distinguishes it from ordinary user permissions is the authority to modify or override other accounts' rights and to perform security-relevant functions — such as key management, account management, network and system administration, and database administration — that ordinary users are not authorized to perform. In practice, the field uses the term to identify a condition that triggers heightened governance: users or accounts requiring administrative privileges on system accounts receive additional scrutiny from organizational personnel — such as the system owner, mission/business owner, or chief information security officer — responsible for approving such accounts and privileged access. Control frameworks invoke it primarily to enforce least-privilege goals: limiting how many accounts carry such privileges reduces the probability of a threat actor abusing them to cause harm.

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A class of access rights — elevated above those granted to standard users — that collectively authorize an account or identity to perform security-sensitive operations that affect the configuration, integrity, or management of a system or network. What distinguishes it from ordinary user permissions is the authority to modify or override other accounts' rights and to perform security-relevant functions — such as key management, account management, network and system administration, and database administration — that ordinary users are not authorized to perform. In practice, the field uses the term to identify a condition that triggers heightened governance: users or accounts requiring administrative privileges on system accounts receive additional scrutiny from organizational personnel — such as the system owner, mission/business owner, or chief information security officer — responsible for approving such accounts and privileged access. Control frameworks invoke it primarily to enforce least-privilege goals: limiting how many accounts carry such privileges reduces the probability of a threat actor abusing them to cause harm.
DR-088 backfill from the noun definition column