system access authorization
163561·updated Aug 30, 2026A set of formally approved permissions and privileges that specify which users, roles, or processes are permitted to interact with a given information system and in what capacity. In NIST SP 800-53 access control guidance, organizations are directed to "define system access authorizations to support separation of duties," framing these authorizations as the structured assignments of access rights that underpin separation-of-duties enforcement. The identification of authorized users and the specification of their access privileges may be defined by account, by account type, or both, and may incorporate additional attributes such as time-of-day or point-of-origin restrictions. In practice, the phrase is used across federal policy and compliance standards as the collective body of documented, approved access entitlements for a system — distinct from the technical mechanism that enforces them — and is subject to management activities such as provisioning, periodic review, and revocation.
Source
system accessthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
- CHAPTER THREE PAGE 1 ACCESS CONTROL Quick link to Access Control summary table
- Information Technology (IT) Access Control (AC) Standard March 14, 2025
- cms access control handbook
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
This phrase is compositional rather than a term of art. It combines three independently defined field concepts — *system* (the information system being protected), *access* (the ability to make use of a resource), and *authorization* (the administrative determination of what access rights a principal may hold) — into a descriptive noun phrase whose meaning is fully predictable from its parts. NIST SP 800-53 uses it in exactly this ordinary, non-definitional way (e.g., "define system access authorizations to support separation of duties"), and no major standards body — NIST, ISO, AICPA, or CIS — assigns it a glossary entry or a meaning that diverges from its literal composition.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- system access authorizations
- possessive
- system access authorization's
- pluralpossessive
- system access authorizations'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A set of formally approved permissions and privileges that specify which users, roles, or processes are permitted to interact with a given information system and in what capacity. In NIST SP 800-53 access control guidance, organizations are directed to "define system access authorizations to support separation of duties," framing these authorizations as the structured assignments of access rights that underpin separation-of-duties enforcement. The identification of authorized users and the specification of their access privileges may be defined by account, by account type, or both, and may incorporate additional attributes such as time-of-day or point-of-origin restrictions. In practice, the phrase is used across federal policy and compliance standards as the collective body of documented, approved access entitlements for a system — distinct from the technical mechanism that enforces them — and is subject to management activities such as provisioning, periodic review, and revocation.DR-088 backfill from the noun definition column