elevated privilege
163582·updated Sep 1, 2026A level of access rights assigned to an account, process, or identity that exceeds standard user permissions — authorizing operations on security functions, restricted data, or system configuration that ordinary accounts cannot perform. As NIST SP 800-171r3 frames it, "privileged accounts refer to accounts that are granted elevated privileges to access resources (including security functions or security-relevant information) that are otherwise restricted for non-privileged accounts." The distinguishing characteristic is not a specific role or account type but the *degree* of permission relative to a baseline: a privileged network account with elevated privileges is "typically allocated to system administrators, network administrators, DBAs, and others who are responsible for system/application control, monitoring, or administration functions" — but the expression covers any identity (human, service, or process) whose rights cross that threshold. NIST also applies the concept to software, noting that critical software "is designed to run with elevated privilege or manage privileges" or "has direct or privileged access to networking or computing resources." In practice, the field use
Source
refer to accounts that are granted elevated privileges to access resources (includingthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- NIST Special Publication 800 NIST SP 800-171r3
- privileged network account - Glossary | CSRC
- Critical Software - Definition & Explanatory Material | NIST
- CIS Critical Security Controls Navigator - v7.1
- What is the Principle of Least Privilege (PoLP)?
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A level of access rights granted to an account, process, or role that exceeds those of a standard user — specifically, rights to perform security-sensitive or administratively consequential actions such as modifying system configuration, managing other accounts, or accessing otherwise restricted resources. As NIST SP 800-171r3 states, such accounts are "granted elevated privileges to access resources (including security functions or security-relevant information) that are otherwise restricted for non-privileged accounts." In practice, the field uses "elevated privilege" as a relative, comparative descriptor: it characterizes any permission level that stands above an established baseline (typically a standard or least-privilege account), encompassing capabilities such as changing security and configuration settings, adding or deleting other user accounts, and installing or disabling software and hardware. The concept anchors core access-control disciplines — least privilege, privileged access management, and separation of duties — and is the governing criterion for deciding which accounts require heightened controls such as MFA, session logging, and periodic review; NIST SP 1800-18
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- elevated privileges
- possessive
- elevated privilege's
- pluralpossessive
- elevated privileges'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A level of access rights assigned to an account, process, or identity that exceeds standard user permissions — authorizing operations on security functions, restricted data, or system configuration that ordinary accounts cannot perform. As NIST SP 800-171r3 frames it, "privileged accounts refer to accounts that are granted elevated privileges to access resources (including security functions or security-relevant information) that are otherwise restricted for non-privileged accounts." The distinguishing characteristic is not a specific role or account type but the *degree* of permission relative to a baseline: a privileged network account with elevated privileges is "typically allocated to system administrators, network administrators, DBAs, and others who are responsible for system/application control, monitoring, or administration functions" — but the expression covers any identity (human, service, or process) whose rights cross that threshold. NIST also applies the concept to software, noting that critical software "is designed to run with elevated privilege or manage privileges" or "has direct or privileged access to networking or computing resources." In practice, the field useDR-088 backfill from the noun definition column