home/dictionary/authorizations to execute

authorizations to execute

nounverified·updated Sep 1, 2026

A compositional phrase, not a coined term of art, describing the set of permissions or access rights that a principal (user, process, or device) has been formally granted to run, invoke, or trigger an action — such as a transaction, script, program, or privileged command — on a system or resource. NIST SP 800-171 frames the underlying concept by requiring that system access be limited "to the types of transactions and functions that authorized users are permitted to execute." In access-control practice, authorizations are expressed as access policies — for example, in the form of an access control list or a capability — and a principal who "does not possess the authorizations to execute" a given action lacks an entry in those policies granting that right. Standards bodies such as NIST require that approved authorizations for logical access to information and system resources be enforced in accordance with applicable access control policies, so the phrase appears naturally in control language to describe the boundary condition where enforcement should block an attempted action.

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A compositional phrase, not a coined term of art, describing the set of permissions or access rights that a principal (user, process, or device) has been formally granted to run, invoke, or trigger an action — such as a transaction, script, program, or privileged command — on a system or resource. NIST SP 800-171 frames the underlying concept by requiring that system access be limited "to the types of transactions and functions that authorized users are permitted to execute." In access-control practice, authorizations are expressed as access policies — for example, in the form of an access control list or a capability — and a principal who "does not possess the authorizations to execute" a given action lacks an entry in those policies granting that right. Standards bodies such as NIST require that approved authorizations for logical access to information and system resources be enforced in accordance with applicable access control policies, so the phrase appears naturally in control language to describe the boundary condition where enforcement should block an attempted action.
DR-088 backfill from the noun definition column