active entity
163597·updated Sep 1, 2026The subject role in an access control model — an entity (generally an individual, process, or device) that causes information to flow among objects or changes system state, as opposed to a passive entity that merely contains or receives information. It is distinguished from a passive object by being the initiating party that requests access to an object or the data within an object; it may be a user, program, or process acting to accomplish a task. The field uses the active/passive distinction to anchor access controls — the security features that govern how users and systems communicate and interact with other systems and resources. The contrast class is equally stable: an object (passive entity) contains information and may be a computer, database, file, program, directory, or field in a table.
Source
control access between active entities or subjects (i.e., users orthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- NIST Special Publication 800-162, Attribute Based Access ...
- CISSP ACCESS CONTROL Flashcards | Quizlet
- Fundamentals of Information Systems Security/Access Control Systems - Wikibooks, open books for an open world
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A participant in an access control model — specifically one that "causes information to flow among objects or changes the system state" — distinguished from a passive entity (object) by its capacity to *initiate* rather than merely receive or hold. Access control mechanisms grant or revoke privileges for active entities (subjects) to access or perform actions on passive entities (objects). An active entity is one that seeks rights to a resource or object, and may be a person, a program, or a process. The designation is relative to a specific access control decision point: in a chain of operations, an entity can be an object in one transaction and immediately become the subject — i.e., the active entity — in the very next transaction it initiates.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- active entities
- possessive
- active entity's
- pluralpossessive
- active entities'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- The subject role in an access control model — an entity (generally an individual, process, or device) that causes information to flow among objects or changes system state, as opposed to a passive entity that merely contains or receives information. It is distinguished from a passive object by being the initiating party that requests access to an object or the data within an object; it may be a user, program, or process acting to accomplish a task. The field uses the active/passive distinction to anchor access controls — the security features that govern how users and systems communicate and interact with other systems and resources. The contrast class is equally stable: an object (passive entity) contains information and may be a computer, database, file, program, directory, or field in a table.DR-088 backfill from the noun definition column