home/glossary/non-security function

non-security function

nounverified·updated Sep 1, 2026

A category of system capability or task — specifically, any operation, feature, or process whose purpose is ordinary business, user-productivity, or operational activity rather than the administration, enforcement, or configuration of security controls. In NIST SP 800-171 and related least-privilege frameworks, it serves as the contrast class to "security functions" (privileged operations such as modifying access policies, managing accounts, or configuring audit mechanisms), and the distinction drives the rule that elevated privileges must not be active during routine work. Practitioners use it to draw the boundary at which a privileged account or role must step down to a non-privileged one, limiting the blast radius of credential compromise or user error during everyday tasks.

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.

Classifications

Entity Type

Unknown75%llm-generatedmulti_axis_classifier_queued.v1
?unassignedlast reviewed

Sensitivity

Regulated80%manual reviewllm:claude-haiku-4-5
?unassignedlast reviewed

Information Class

unclassified

Variants

plural
non-security functions
possessive
non-security function's
pluralpossessive
non-security functions'