home/glossary/system support function

system support function

nounid 163566·updated Aug 30, 2026
verified

A category of privileged IT activities — such as configuration management, quality assurance and testing, system management, programming, and network security — that must be distributed across multiple individuals or roles rather than concentrated in any one person. It is distinguished from mission or business functions by its technical/administrative character: these are the internal operational tasks that keep a system running and secure, as opposed to the outputs the system produces for the organization. In the field, the concept is invoked as one of the three main mechanisms for implementing separation of duties (NIST SP 800-53 AC-5; NIST SP 800-171 control 3.1.4), alongside dividing mission functions and preventing administrators from holding cross-cutting privileges such as both access-control administration and audit administration.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0188
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
among different individuals or roles, conducting systemthe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A category of operational responsibilities — such as configuration management, quality assurance and testing, system management, programming, and network security — that collectively maintain, operate, or oversee an information system rather than directly advancing its mission or business output. In NIST's treatment of separation of duties, the concept is used to distinguish these infrastructure-and-oversight tasks from mission functions, with the requirement that they be divided among different individuals or roles. The rationale is that separating such functions addresses the potential for abuse of authorized privileges and helps reduce the risk of malevolent activity without collusion. Practically, frameworks such as NIST SP 800-53 AC-5 apply this by requiring that security personnel who administer access control functions do not also administer audit functions, and that organizations consider the entirety of systems and system components when developing separation-of-duties policy.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems2 citations · 2 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.04.b ¶ 103.01.04.b ¶ 1

Classifications

Entity Type

Process85%llm-generatedllm:claude-haiku-4-5

Sensitivity

Restricted80%llm-generatedllm:claude-haiku-4-5

Information Class

Cui70%llm-generatedllm:claude-haiku-4-5

Variants

plural
system support functions
possessive
system support function's
pluralpossessive
system support functions'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A category of privileged IT activities — such as configuration management, quality assurance and testing, system management, programming, and network security — that must be distributed across multiple individuals or roles rather than concentrated in any one person. It is distinguished from mission or business functions by its technical/administrative character: these are the internal operational tasks that keep a system running and secure, as opposed to the outputs the system produces for the organization. In the field, the concept is invoked as one of the three main mechanisms for implementing separation of duties (NIST SP 800-53 AC-5; NIST SP 800-171 control 3.1.4), alongside dividing mission functions and preventing administrators from holding cross-cutting privileges such as both access-control administration and audit administration.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.