active entity
The subject role in an access control model — an entity (generally an individual, process, or device) that causes information to flow among objects or changes system state, as opposed to a passive entity that merely contains or receives information. It is distinguished from a passive object by being the initiating party that requests access to an object or the data within an object; it may be a user, program, or process acting to accomplish a task. The field uses the active/passive distinction to anchor access controls — the security features that govern how users and systems communicate and interact with other systems and resources. The contrast class is equally stable: an object (passive entity) contains information and may be a computer, database, file, program, directory, or field in a table.
Senses
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- active entities
- possessive
- active entity's
- pluralpossessive
- active entities'