home/glossary/Access authorization

Access authorization

nounverified·updated Aug 30, 2026

The set of permissions and privileges formally assigned to an account or identity that determine what resources, functions, or data that account may access and what operations it may perform. Derived from an administrative decision — made by a system owner, security officer, or policy — it is distinct from both the authentication event that precedes access and the enforcement mechanism that implements it. Across NIST SP 800-53, NIST SP 800-171, and the NIST Cybersecurity Framework, the term is used interchangeably with *privileges* and treated as a managed attribute of an account: organizations must specify, review, and enforce these authorizations per least-privilege and separation-of-duties requirements.

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 9 citations in that document; a definition is pending curation.

Classifications

Entity Type

Control85%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

Regulated90%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Information Class

unclassified

Variants

plural
Access authorizations
possessive
Access authorization's
pluralpossessive
Access authorizations'