Access authorization
163498·updated Aug 30, 2026The set of permissions and privileges formally assigned to an account or identity that determine what resources, functions, or data that account may access and what operations it may perform. Derived from an administrative decision — made by a system owner, security officer, or policy — it is distinct from both the authentication event that precedes access and the enforcement mechanism that implements it. Across NIST SP 800-53, NIST SP 800-171, and the NIST Cybersecurity Framework, the term is used interchangeably with *privileges* and treated as a managed attribute of an account: organizations must specify, review, and enforce these authorizations per least-privilege and separation-of-duties requirements.
Source
Access authorizations (i.e., privileges) for each account.the sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- AC-6(1): Authorize Access To Security Functions - CSF Tools
- 03.01.01: Account Management - CSF Tools
- AC: Access Control - CSF Tools
- PR.AC-4: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties - CSF Tools
- CHAPTER THREE PAGE 1 ACCESS CONTROL Quick link to Access Control summary table
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
The set of permissions and privileges formally assigned to an account or identity that determine what resources, functions, or data that account may access and what operations it may perform. Derived from an administrative decision — made by a system owner, security officer, or policy — it is distinct from both the authentication event that precedes access and the enforcement mechanism that implements it. Across NIST SP 800-53, NIST SP 800-171, and the NIST Cybersecurity Framework, the term is used interchangeably with *privileges* and treated as a managed attribute of an account: organizations must specify, review, and enforce these authorizations per least-privilege and separation-of-duties requirements.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- Access authorizations
- possessive
- Access authorization's
- pluralpossessive
- Access authorizations'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 9 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- The set of permissions and privileges formally assigned to an account or identity that determine what resources, functions, or data that account may access and what operations it may perform. Derived from an administrative decision — made by a system owner, security officer, or policy — it is distinct from both the authentication event that precedes access and the enforcement mechanism that implements it. Across NIST SP 800-53, NIST SP 800-171, and the NIST Cybersecurity Framework, the term is used interchangeably with *privileges* and treated as a managed attribute of an account: organizations must specify, review, and enforce these authorizations per least-privilege and separation-of-duties requirements.DR-088 backfill from the noun definition column