access control function
163593·updated Sep 1, 2026A capability or software mechanism, within a system or application, whose specific role is to evaluate a subject's credentials or authorizations and enforce a policy decision — granting or denying the requested access to a resource, service, or operation. It is the operative unit that translates an access-control policy into a runtime enforcement action, distinct from the broader policy, model, or administrative process that surrounds it. In standards and legal instruments — including ITU-T security definitions and computer-crime law — the term names this enforcement function as a discrete, identifiable component: the part of a system that checks an identity code and removes or maintains restrictions on a protected use.
Source
access controlthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- Access control function | The IT Law Wiki | Fandom
- Access control function definition
- Access Control (Authorization)
- nvlpubs.nist.gov
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A mechanism — whether implemented in software, hardware, or policy — that performs the decision-making and enforcement steps by which a system determines whether a subject (user, process, or device) is permitted to perform a requested action on a protected resource. In the security administration model, there is a security administration function for specifying the authorization database that acts as an input to the access control function, making it the runtime enforcement component that consumes policy and produces permit/deny decisions. One statutory definition (Japan's Unauthorized Computer Access Law, as rendered on Law Insider) frames it as a function added to a computer that automatically controls a specific use and removes restrictions on that use after confirming the input identification code is valid — a narrow but formally defined instantiation of the broader concept. Across the field the phrase is used descriptively rather than as a single standardized term: NIST and FIPS define the overarching activity as "the process of granting or denying specific requests to obtain and use information and related information processing services", with "access control function" simpl
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- access control functions
- possessive
- access control function's
- pluralpossessive
- access control functions'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A capability or software mechanism, within a system or application, whose specific role is to evaluate a subject's credentials or authorizations and enforce a policy decision — granting or denying the requested access to a resource, service, or operation. It is the operative unit that translates an access-control policy into a runtime enforcement action, distinct from the broader policy, model, or administrative process that surrounds it. In standards and legal instruments — including ITU-T security definitions and computer-crime law — the term names this enforcement function as a discrete, identifiable component: the part of a system that checks an identity code and removes or maintains restrictions on a protected use.DR-088 backfill from the noun definition column