system usage
A characterization, established at provisioning time, of the purposes, functions, and scope for which a particular user or role is authorized to interact with an information system. It is distinguished from mere access authorization by its forward-looking, descriptive quality: it captures *what the system is being used for* by a given account holder—mission function, business role, data types handled—not simply *whether* access is permitted. In access-control and account-management practice, access to a system is granted based on a valid access authorization, *intended system usage*, and other attributes required by the organization or associated missions/business functions. Correspondingly, account managers must be notified when *system usage* or need-to-know changes for an individual, making it a live attribute that is re-evaluated throughout the account lifecycle, not just at onboarding.
Senses
No definition is given in NIST SP 800-171r3. The term is attested in use at 3 citations in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- system usages
- possessive
- system usage's
- pluralpossessive
- system usages'