non-privileged user
A category of system account or role whose authorization scope is bounded to ordinary, task-specific functions and explicitly excludes security-relevant or administrative operations such as establishing accounts, configuring access controls, performing system integrity checks, or circumventing protective mechanisms. As defined in NIST SP 800-171, non-privileged users are individuals that do not possess appropriate authorizations — that is, they lack the elevated trust granted to privileged users. A privileged user, by contrast, is one "authorized (and therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform" (NIST SP 800-53 Rev. 5 / CNSSI 4009-2022), so a non-privileged user occupies the complementary set. In practice, the field uses the expression to enforce the principle of least privilege: non-privileged user accounts must be used by default and elevated to root or administrator only when necessary, so that routine and daily activities are performed under non-privileged accounts, with Administrator/Root reserved for specific administrative actions. Controls such as NIST SP 800-53 AC-6 and NIST SP 800-171 3.1.7 operationalize th
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · legacy_primary
- A category of system account or role whose authorization scope is bounded to ordinary, task-specific functions and explicitly excludes security-relevant or administrative operations such as establishing accounts, configuring access controls, performing system integrity checks, or circumventing protective mechanisms. As defined in NIST SP 800-171, non-privileged users are individuals that do not possess appropriate authorizations — that is, they lack the elevated trust granted to privileged users. A privileged user, by contrast, is one "authorized (and therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform" (NIST SP 800-53 Rev. 5 / CNSSI 4009-2022), so a non-privileged user occupies the complementary set. In practice, the field uses the expression to enforce the principle of least privilege: non-privileged user accounts must be used by default and elevated to root or administrator only when necessary, so that routine and daily activities are performed under non-privileged accounts, with Administrator/Root reserved for specific administrative actions. Controls such as NIST SP 800-53 AC-6 and NIST SP 800-171 3.1.7 operationalize thDR-088 backfill from the noun definition column