home/glossary/authorized privilege

authorized privilege

nounverified·updated Aug 30, 2026

** A set of elevated access rights, permissions, or capabilities that have been formally granted to a user, role, or process by an authorizing entity within a defined access-control policy. The expression functions as the collective object of access-governance controls — particularly least privilege and separation of duties — which exist precisely because such rights, though legitimately held, remain a vector for insider abuse or insider threat if concentrated without checks. The principle of least privilege is applied with the goal of authorized privileges no higher than necessary to accomplish required organizational missions or business functions. In practice, separation of duties addresses the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activity without collusion — making "authorized privileges" the specific threat surface that controls such as role separation, audit logging of privileged-function execution, and periodic access reviews are designed to govern. **VERDICT:** COMPOSITIONAL The expression is not a defined term of art with its own glossary entry in NIST SP 800-53, NIST SP 800-171, or related authority documents. It is a t

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.

Classifications

Entity Type

Capability80%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

Regulated75%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Information Class

unclassified

Variants

plural
authorized privileges
possessive
authorized privilege's
pluralpossessive
authorized privileges'