support function
A category of operational activity within a system or organization that enables, maintains, or oversees the primary mission — encompassing roles such as configuration management, quality assurance, testing, system administration, programming, and network security. NIST distinguishes "support functions" from "mission or business functions," treating them as the infrastructure-oriented counterpart to direct mission execution. In the field, the expression is used principally in the context of separation of duties: organizations are required to divide mission functions and support functions among different individuals or roles — and to further divide system support functions across distinct individuals even within that category (e.g., quality assurance, configuration management, network security, system management, assessments, and programming) — so that no single person accumulates enough access or authority to commit or conceal malfeasance. This directly addresses the potential for abuse of authorized privileges and reduces the risk of malevolent activity without collusion.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A category of operational activity within a system or organization that enables, maintains, or oversees the primary mission — encompassing roles such as configuration management, quality assurance, testing, system administration, programming, and network security. NIST distinguishes "support functions" from "mission or business functions," treating them as the infrastructure-oriented counterpart to direct mission execution. In the field, the expression is used principally in the context of separation of duties: organizations are required to divide mission functions and support functions among different individuals or roles — and to further divide system support functions across distinct individuals even within that category (e.g., quality assurance, configuration management, network security, system management, assessments, and programming) — so that no single person accumulates enough access or authority to commit or conceal malfeasance. This directly addresses the potential for abuse of authorized privileges and reduces the risk of malevolent activity without collusion.DR-088 backfill from the noun definition column