elevated privilege
A level of access rights assigned to an account, process, or identity that exceeds standard user permissions — authorizing operations on security functions, restricted data, or system configuration that ordinary accounts cannot perform. As NIST SP 800-171r3 frames it, "privileged accounts refer to accounts that are granted elevated privileges to access resources (including security functions or security-relevant information) that are otherwise restricted for non-privileged accounts." The distinguishing characteristic is not a specific role or account type but the *degree* of permission relative to a baseline: a privileged network account with elevated privileges is "typically allocated to system administrators, network administrators, DBAs, and others who are responsible for system/application control, monitoring, or administration functions" — but the expression covers any identity (human, service, or process) whose rights cross that threshold. NIST also applies the concept to software, noting that critical software "is designed to run with elevated privilege or manage privileges" or "has direct or privileged access to networking or computing resources." In practice, the field use
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A level of access rights assigned to an account, process, or identity that exceeds standard user permissions — authorizing operations on security functions, restricted data, or system configuration that ordinary accounts cannot perform. As NIST SP 800-171r3 frames it, "privileged accounts refer to accounts that are granted elevated privileges to access resources (including security functions or security-relevant information) that are otherwise restricted for non-privileged accounts." The distinguishing characteristic is not a specific role or account type but the *degree* of permission relative to a baseline: a privileged network account with elevated privileges is "typically allocated to system administrators, network administrators, DBAs, and others who are responsible for system/application control, monitoring, or administration functions" — but the expression covers any identity (human, service, or process) whose rights cross that threshold. NIST also applies the concept to software, noting that critical software "is designed to run with elevated privilege or manage privileges" or "has direct or privileged access to networking or computing resources." In practice, the field useDR-088 backfill from the noun definition column