non-privileged access
A category of system access in which the account, role, or session carries only standard user permissions and is explicitly excluded from administrative, security-function, or other elevated capabilities reserved for privileged users. It is distinguished from privileged access by the absence of authorizations to execute security-relevant operations such as modifying system configurations, managing accounts, or administering cryptographic functions. In practice, frameworks use it both as a classification of access type and as an operational requirement — mandating that even users who hold privileged accounts switch to non-privileged accounts or roles whenever they perform ordinary, non-security functions, thereby limiting the attack surface exposed during routine work.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A category of system access in which the account, role, or session carries only standard user permissions and is explicitly excluded from administrative, security-function, or other elevated capabilities reserved for privileged users. It is distinguished from privileged access by the absence of authorizations to execute security-relevant operations such as modifying system configurations, managing accounts, or administering cryptographic functions. In practice, frameworks use it both as a classification of access type and as an operational requirement — mandating that even users who hold privileged accounts switch to non-privileged accounts or roles whenever they perform ordinary, non-security functions, thereby limiting the attack surface exposed during routine work.DR-088 backfill from the noun definition column