home/glossary/access control function

access control function

nounid 163593·updated Sep 1, 2026
verified

A capability or software mechanism, within a system or application, whose specific role is to evaluate a subject's credentials or authorizations and enforce a policy decision — granting or denying the requested access to a resource, service, or operation. It is the operative unit that translates an access-control policy into a runtime enforcement action, distinct from the broader policy, model, or administrative process that surrounds it. In standards and legal instruments — including ITU-T security definitions and computer-crime law — the term names this enforcement function as a discrete, identifiable component: the part of a system that checks an identity code and removes or maintains restrictions on a protected use.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0188
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
access controlthe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A mechanism — whether implemented in software, hardware, or policy — that performs the decision-making and enforcement steps by which a system determines whether a subject (user, process, or device) is permitted to perform a requested action on a protected resource. In the security administration model, there is a security administration function for specifying the authorization database that acts as an input to the access control function, making it the runtime enforcement component that consumes policy and produces permit/deny decisions. One statutory definition (Japan's Unauthorized Computer Access Law, as rendered on Law Insider) frames it as a function added to a computer that automatically controls a specific use and removes restrictions on that use after confirming the input identification code is valid — a narrow but formally defined instantiation of the broader concept. Across the field the phrase is used descriptively rather than as a single standardized term: NIST and FIPS define the overarching activity as "the process of granting or denying specific requests to obtain and use information and related information processing services", with "access control function" simpl

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.04.b ¶ 1

Classifications

Entity Type

Control92%rule-basedr:entity.control.safeguard.v1

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
access control functions
possessive
access control function's
pluralpossessive
access control functions'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A capability or software mechanism, within a system or application, whose specific role is to evaluate a subject's credentials or authorizations and enforce a policy decision — granting or denying the requested access to a resource, service, or operation. It is the operative unit that translates an access-control policy into a runtime enforcement action, distinct from the broader policy, model, or administrative process that surrounds it. In standards and legal instruments — including ITU-T security definitions and computer-crime law — the term names this enforcement function as a discrete, identifiable component: the part of a system that checks an identity code and removes or maintains restrictions on a protected use.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.