home/dictionary/system process

system process

nounverified·updated Aug 30, 2026

An active security principal—specifically, an executing software process on a computing system—that has been granted an identity and access rights so it can perform actions on behalf of a human user without that user being directly present. NIST (SP 800-37 Rev. 2) treats it as one of the two forms a "system user" may take: "an individual or (system) process acting on behalf of an individual that is authorized to access information and information systems to perform assigned duties." In access-control frameworks such as NIST SP 800-53 and SP 800-171, system processes are classified alongside human users as **active entities or subjects** that access control policies must govern, standing in contrast to passive objects such as devices, files, records, and domains. Practically, if a user launches an application or background tool, that application runs as the user and "is acting on behalf of the user," meaning any process running under a user's authority must be confined to the same access permissions as that user and no more.

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 5 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
An active security principal—specifically, an executing software process on a computing system—that has been granted an identity and access rights so it can perform actions on behalf of a human user without that user being directly present. NIST (SP 800-37 Rev. 2) treats it as one of the two forms a "system user" may take: "an individual or (system) process acting on behalf of an individual that is authorized to access information and information systems to perform assigned duties." In access-control frameworks such as NIST SP 800-53 and SP 800-171, system processes are classified alongside human users as **active entities or subjects** that access control policies must govern, standing in contrast to passive objects such as devices, files, records, and domains. Practically, if a user launches an application or background tool, that application runs as the user and "is acting on behalf of the user," meaning any process running under a user's authority must be confined to the same access permissions as that user and no more.
DR-088 backfill from the noun definition column