home/glossary/system access authorization

system access authorization

nounverified·updated Aug 30, 2026

A set of formally approved permissions and privileges that specify which users, roles, or processes are permitted to interact with a given information system and in what capacity. In NIST SP 800-53 access control guidance, organizations are directed to "define system access authorizations to support separation of duties," framing these authorizations as the structured assignments of access rights that underpin separation-of-duties enforcement. The identification of authorized users and the specification of their access privileges may be defined by account, by account type, or both, and may incorporate additional attributes such as time-of-day or point-of-origin restrictions. In practice, the phrase is used across federal policy and compliance standards as the collective body of documented, approved access entitlements for a system — distinct from the technical mechanism that enforces them — and is subject to management activities such as provisioning, periodic review, and revocation.

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.

Classifications

Entity Type

Requirement85%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

Regulated90%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Information Class

Cui70%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Variants

plural
system access authorizations
possessive
system access authorization's
pluralpossessive
system access authorizations'