home/glossary/system usage

system usage

nounid 163499·updated Aug 30, 2026
verified

A characterization, established at provisioning time, of the purposes, functions, and scope for which a particular user or role is authorized to interact with an information system. It is distinguished from mere access authorization by its forward-looking, descriptive quality: it captures *what the system is being used for* by a given account holder—mission function, business role, data types handled—not simply *whether* access is permitted. In access-control and account-management practice, access to a system is granted based on a valid access authorization, *intended system usage*, and other attributes required by the organization or associated missions/business functions. Correspondingly, account managers must be notified when *system usage* or need-to-know changes for an individual, making it a live attribute that is re-evaluated throughout the account lifecycle, not just at onboarding.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0148
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
Intended system usage.the sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A characterization, established at provisioning time, of the purposes, functions, and scope for which a particular user or role is authorized to interact with an information system. It is distinguished from mere access authorization by its forward-looking, descriptive quality: it captures *what the system is being used for* by a given account holder—mission function, business role, data types handled—not simply *whether* access is permitted. In access-control and account-management practice, access to a system is granted based on a valid access authorization, *intended system usage*, and other attributes required by the organization or associated missions/business functions. Correspondingly, account managers must be notified when *system usage* or need-to-know changes for an individual, making it a live attribute that is re-evaluated throughout the account lifecycle, not just at onboarding.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems3 citations · 3 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.01.d.203.01.01.g.303.15.03.a

Classifications

Entity Type

Requirement85%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated75%llm-generatedllm:claude-haiku-4-5

Information Class

unclassified

Variants

plural
system usages
possessive
system usage's
pluralpossessive
system usages'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 3 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A characterization, established at provisioning time, of the purposes, functions, and scope for which a particular user or role is authorized to interact with an information system. It is distinguished from mere access authorization by its forward-looking, descriptive quality: it captures *what the system is being used for* by a given account holder—mission function, business role, data types handled—not simply *whether* access is permitted. In access-control and account-management practice, access to a system is granted based on a valid access authorization, *intended system usage*, and other attributes required by the organization or associated missions/business functions. Correspondingly, account managers must be notified when *system usage* or need-to-know changes for an individual, making it a live attribute that is re-evaluated throughout the account lifecycle, not just at onboarding.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.