super user account
A privileged user account — one class of which is specifically designated for system administration — that carries elevated or unrestricted rights across files, directories, commands, and system-wide configuration, beyond what ordinary users are authorized to perform. In practice, system administrators use privileged "super user" accounts to manage information technology assets; despite being described as the "keys to the kingdom," these accounts rarely receive direct oversight or technical control of how they are used. Because such an account is capable of making unrestricted, potentially adverse, system-wide changes, the principle of least privilege recommends that most users and applications run under ordinary accounts for their normal work. The field uses the expression as a broad label for the highest-privilege account class — covering OS root/administrator accounts, application-level all-access accounts, and administratively scoped super-user roles — and treats controlling, auditing, and restricting such accounts as a core privileged access management (PAM) concern.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A privileged user account — one class of which is specifically designated for system administration — that carries elevated or unrestricted rights across files, directories, commands, and system-wide configuration, beyond what ordinary users are authorized to perform. In practice, system administrators use privileged "super user" accounts to manage information technology assets; despite being described as the "keys to the kingdom," these accounts rarely receive direct oversight or technical control of how they are used. Because such an account is capable of making unrestricted, potentially adverse, system-wide changes, the principle of least privilege recommends that most users and applications run under ordinary accounts for their normal work. The field uses the expression as a broad label for the highest-privilege account class — covering OS root/administrator accounts, application-level all-access accounts, and administratively scoped super-user roles — and treats controlling, auditing, and restricting such accounts as a core privileged access management (PAM) concern.DR-088 backfill from the noun definition column