home/glossary/elevated privilege

elevated privilege

nounid 163582·updated Sep 1, 2026
verified

A level of access rights assigned to an account, process, or identity that exceeds standard user permissions — authorizing operations on security functions, restricted data, or system configuration that ordinary accounts cannot perform. As NIST SP 800-171r3 frames it, "privileged accounts refer to accounts that are granted elevated privileges to access resources (including security functions or security-relevant information) that are otherwise restricted for non-privileged accounts." The distinguishing characteristic is not a specific role or account type but the *degree* of permission relative to a baseline: a privileged network account with elevated privileges is "typically allocated to system administrators, network administrators, DBAs, and others who are responsible for system/application control, monitoring, or administration functions" — but the expression covers any identity (human, service, or process) whose rights cross that threshold. NIST also applies the concept to software, noting that critical software "is designed to run with elevated privilege or manage privileges" or "has direct or privileged access to networking or computing resources." In practice, the field use

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0206
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
refer to accounts that are granted elevated privileges to access resources (includingthe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A level of access rights granted to an account, process, or role that exceeds those of a standard user — specifically, rights to perform security-sensitive or administratively consequential actions such as modifying system configuration, managing other accounts, or accessing otherwise restricted resources. As NIST SP 800-171r3 states, such accounts are "granted elevated privileges to access resources (including security functions or security-relevant information) that are otherwise restricted for non-privileged accounts." In practice, the field uses "elevated privilege" as a relative, comparative descriptor: it characterizes any permission level that stands above an established baseline (typically a standard or least-privilege account), encompassing capabilities such as changing security and configuration settings, adding or deleting other user accounts, and installing or disabling software and hardware. The concept anchors core access-control disciplines — least privilege, privileged access management, and separation of duties — and is the governing criterion for deciding which accounts require heightened controls such as MFA, session logging, and periodic review; NIST SP 1800-18

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.06.b ¶ 1

Classifications

Entity Type

Unknown75%llm-generatedmulti_axis_classifier_queued.v1

Sensitivity

Regulated85%manual reviewllm:claude-haiku-4-5

Information Class

70%llm-generatedmulti_axis_classifier_queued.v1

Variants

plural
elevated privileges
possessive
elevated privilege's
pluralpossessive
elevated privileges'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A level of access rights assigned to an account, process, or identity that exceeds standard user permissions — authorizing operations on security functions, restricted data, or system configuration that ordinary accounts cannot perform. As NIST SP 800-171r3 frames it, "privileged accounts refer to accounts that are granted elevated privileges to access resources (including security functions or security-relevant information) that are otherwise restricted for non-privileged accounts." The distinguishing characteristic is not a specific role or account type but the *degree* of permission relative to a baseline: a privileged network account with elevated privileges is "typically allocated to system administrators, network administrators, DBAs, and others who are responsible for system/application control, monitoring, or administration functions" — but the expression covers any identity (human, service, or process) whose rights cross that threshold. NIST also applies the concept to software, noting that critical software "is designed to run with elevated privilege or manage privileges" or "has direct or privileged access to networking or computing resources." In practice, the field use
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.