support function
163565·updated Aug 30, 2026A category of operational activity within a system or organization that enables, maintains, or oversees the primary mission — encompassing roles such as configuration management, quality assurance, testing, system administration, programming, and network security. NIST distinguishes "support functions" from "mission or business functions," treating them as the infrastructure-oriented counterpart to direct mission execution. In the field, the expression is used principally in the context of separation of duties: organizations are required to divide mission functions and support functions among different individuals or roles — and to further divide system support functions across distinct individuals even within that category (e.g., quality assurance, configuration management, network security, system management, assessments, and programming) — so that no single person accumulates enough access or authority to commit or conceal malfeasance. This directly addresses the potential for abuse of authorized privileges and reduces the risk of malevolent activity without collusion.
Source
and support functions among different individuals or roles, conducting system support functions with different individuals or roles (e.g., quality assurance,the sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
- AC-5: Separation of Duties - CSF Tools
- 03.01.04: Separation of Duties - CSF Tools
- Separation of Duties from NIST 800-171 Rev 3 framework | SAMMY
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A category of organizational or system-level duties — such as configuration management, quality assurance, testing, system administration, programming, and network security — that underpin and enable mission or business operations without directly constituting that mission. In security and compliance frameworks (prominently NIST SP 800-53 and SP 800-171), the category is invoked specifically to distinguish infrastructure and administrative tasks from operational/mission tasks for purposes of separation-of-duties analysis: separation of duties includes dividing mission or business functions and support functions among different individuals or roles, conducting system support functions with different individuals, and ensuring that security personnel who administer access control functions do not also administer audit functions. The field uses it as a practical grouping that identifies which roles hold technical power over a system's underpinnings — and therefore which role combinations must be kept separate to prevent privilege abuse or collusion.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- support functions
- possessive
- support function's
- pluralpossessive
- support functions'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A category of operational activity within a system or organization that enables, maintains, or oversees the primary mission — encompassing roles such as configuration management, quality assurance, testing, system administration, programming, and network security. NIST distinguishes "support functions" from "mission or business functions," treating them as the infrastructure-oriented counterpart to direct mission execution. In the field, the expression is used principally in the context of separation of duties: organizations are required to divide mission functions and support functions among different individuals or roles — and to further divide system support functions across distinct individuals even within that category (e.g., quality assurance, configuration management, network security, system management, assessments, and programming) — so that no single person accumulates enough access or authority to commit or conceal malfeasance. This directly addresses the potential for abuse of authorized privileges and reduces the risk of malevolent activity without collusion.DR-088 backfill from the noun definition column