home/dictionary/elevated privilege

elevated privilege

nounverified·updated Sep 1, 2026

A level of access rights assigned to an account, process, or identity that exceeds standard user permissions — authorizing operations on security functions, restricted data, or system configuration that ordinary accounts cannot perform. As NIST SP 800-171r3 frames it, "privileged accounts refer to accounts that are granted elevated privileges to access resources (including security functions or security-relevant information) that are otherwise restricted for non-privileged accounts." The distinguishing characteristic is not a specific role or account type but the *degree* of permission relative to a baseline: a privileged network account with elevated privileges is "typically allocated to system administrators, network administrators, DBAs, and others who are responsible for system/application control, monitoring, or administration functions" — but the expression covers any identity (human, service, or process) whose rights cross that threshold. NIST also applies the concept to software, noting that critical software "is designed to run with elevated privilege or manage privileges" or "has direct or privileged access to networking or computing resources." In practice, the field use

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A level of access rights assigned to an account, process, or identity that exceeds standard user permissions — authorizing operations on security functions, restricted data, or system configuration that ordinary accounts cannot perform. As NIST SP 800-171r3 frames it, "privileged accounts refer to accounts that are granted elevated privileges to access resources (including security functions or security-relevant information) that are otherwise restricted for non-privileged accounts." The distinguishing characteristic is not a specific role or account type but the *degree* of permission relative to a baseline: a privileged network account with elevated privileges is "typically allocated to system administrators, network administrators, DBAs, and others who are responsible for system/application control, monitoring, or administration functions" — but the expression covers any identity (human, service, or process) whose rights cross that threshold. NIST also applies the concept to software, noting that critical software "is designed to run with elevated privilege or manage privileges" or "has direct or privileged access to networking or computing resources." In practice, the field use
DR-088 backfill from the noun definition column