home/glossary/system access authorization

system access authorization

nounid 163561·updated Aug 30, 2026
verified

A set of formally approved permissions and privileges that specify which users, roles, or processes are permitted to interact with a given information system and in what capacity. In NIST SP 800-53 access control guidance, organizations are directed to "define system access authorizations to support separation of duties," framing these authorizations as the structured assignments of access rights that underpin separation-of-duties enforcement. The identification of authorized users and the specification of their access privileges may be defined by account, by account type, or both, and may incorporate additional attributes such as time-of-day or point-of-origin restrictions. In practice, the phrase is used across federal policy and compliance standards as the collective body of documented, approved access entitlements for a system — distinct from the technical mechanism that enforces them — and is subject to management activities such as provisioning, periodic review, and revocation.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0186
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
system accessthe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

This phrase is compositional rather than a term of art. It combines three independently defined field concepts — *system* (the information system being protected), *access* (the ability to make use of a resource), and *authorization* (the administrative determination of what access rights a principal may hold) — into a descriptive noun phrase whose meaning is fully predictable from its parts. NIST SP 800-53 uses it in exactly this ordinary, non-definitional way (e.g., "define system access authorizations to support separation of duties"), and no major standards body — NIST, ISO, AICPA, or CIS — assigns it a glossary entry or a meaning that diverges from its literal composition.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems2 citations · 2 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.04.b03.09.02.b.2 ¶ 2

Classifications

Entity Type

Requirement85%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated90%llm-generatedllm:claude-haiku-4-5

Information Class

Cui70%llm-generatedllm:claude-haiku-4-5

Variants

plural
system access authorizations
possessive
system access authorization's
pluralpossessive
system access authorizations'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A set of formally approved permissions and privileges that specify which users, roles, or processes are permitted to interact with a given information system and in what capacity. In NIST SP 800-53 access control guidance, organizations are directed to "define system access authorizations to support separation of duties," framing these authorizations as the structured assignments of access rights that underpin separation-of-duties enforcement. The identification of authorized users and the specification of their access privileges may be defined by account, by account type, or both, and may incorporate additional attributes such as time-of-day or point-of-origin restrictions. In practice, the phrase is used across federal policy and compliance standards as the collective body of documented, approved access entitlements for a system — distinct from the technical mechanism that enforces them — and is subject to management activities such as provisioning, periodic review, and revocation.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.