home/glossary/access control

access control

nounid 1394·updated May 9, 2026
verified

A system or measures that limit the retrieving, obtaining, or examining of information, or information processing resources, to persons or applications authorized by the system or data classification.

MWE

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems19 citations · 19 machine-matched · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
3.103.01.02 ¶ 103.01.02 ¶ 203.01.04.b ¶ 103.01.05.d ¶ 103.01.08.b ¶ 203.01.12.c03.01.12.d ¶ 103.01.1803.03.02.b ¶ 103.03.03.b ¶ 103.03.07.b ¶ 103.04.11.b ¶ 103.05.02 ¶ 203.10.07.e ¶ 103.10.07.e ¶ 203.10.083.2.1 ¶ 403.2.2 ¶ 137

Classifications

Entity Type

Control95%rule-basedr:entity.control.safeguard.v1

Sensitivity

unclassified

Information Class

unclassified

Variants

synonym
adequate protection for the documented information
plural
access controls
possessive
access control's
pluralpossessive
access controls'

Framework definitions

SANS Glossary of Security Terms1 senseview framework →
§1
Access Control ensures that resources are only granted to those users who are entitled to them.
National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1
The process of granting or denying specific requests for or attempts to: 1) obtain and use information and related information processing services; and 2) enter specific physical facilities.
NIST Cybersecurity Framework1 senseview framework →
§1
A system or measures that limit the retrieving, obtaining, or examining of information, or information processing resources, to persons or applications authorized by the system or data classification.
FFIEC Cybersecurity Assessment Tool, Baseline, May 20171 senseview framework →
§1
A system or measures that limit the retrieving, obtaining, or examining of information, or information processing resources, to persons or applications authorized by the system or data classification.
NY DFS Part 500 (NYCRR Title 23, Chapter 1, Part 500)1 senseview framework →
§1
A system or measures that limit the retrieving, obtaining, or examining of information, or information processing resources, to persons or applications authorized by the system or data classification.
NIST SP 800-171r31 senseview framework →
§1 · attested_usage_pack_match
No definition is given in NIST SP 800-171r3. The term is attested in use at 19 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
A system or measures that limit the retrieving, obtaining, or examining of information, or information processing resources, to persons or applications authorized by the system or data classification.
DR-088 backfill from the noun definition column

Outgoing relationships

Incoming relationships

related