Access authorization
The set of permissions and privileges formally assigned to an account or identity that determine what resources, functions, or data that account may access and what operations it may perform. Derived from an administrative decision — made by a system owner, security officer, or policy — it is distinct from both the authentication event that precedes access and the enforcement mechanism that implements it. Across NIST SP 800-53, NIST SP 800-171, and the NIST Cybersecurity Framework, the term is used interchangeably with *privileges* and treated as a managed attribute of an account: organizations must specify, review, and enforce these authorizations per least-privilege and separation-of-duties requirements.
Senses
No definition is given in NIST SP 800-171r3. The term is attested in use at 9 citations in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- Access authorizations
- possessive
- Access authorization's
- pluralpossessive
- Access authorizations'