system usage
163499·updated Aug 30, 2026A characterization, established at provisioning time, of the purposes, functions, and scope for which a particular user or role is authorized to interact with an information system. It is distinguished from mere access authorization by its forward-looking, descriptive quality: it captures *what the system is being used for* by a given account holder—mission function, business role, data types handled—not simply *whether* access is permitted. In access-control and account-management practice, access to a system is granted based on a valid access authorization, *intended system usage*, and other attributes required by the organization or associated missions/business functions. Correspondingly, account managers must be notified when *system usage* or need-to-know changes for an individual, making it a live attribute that is re-evaluated throughout the account lifecycle, not just at onboarding.
Source
Intended system usage.the sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- Access Control Policy and Procedures
- AC-2 - NIST 800-53 r5 Control Explorer - GRC Academy
- – AC-2 ACCOUNT MANAGEMENT | NIST SP 800-53
- Information System Access Control - Revision 2 | Food Safety and Inspection Service
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A characterization, established at provisioning time, of the purposes, functions, and scope for which a particular user or role is authorized to interact with an information system. It is distinguished from mere access authorization by its forward-looking, descriptive quality: it captures *what the system is being used for* by a given account holder—mission function, business role, data types handled—not simply *whether* access is permitted. In access-control and account-management practice, access to a system is granted based on a valid access authorization, *intended system usage*, and other attributes required by the organization or associated missions/business functions. Correspondingly, account managers must be notified when *system usage* or need-to-know changes for an individual, making it a live attribute that is re-evaluated throughout the account lifecycle, not just at onboarding.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- system usages
- possessive
- system usage's
- pluralpossessive
- system usages'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 3 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A characterization, established at provisioning time, of the purposes, functions, and scope for which a particular user or role is authorized to interact with an information system. It is distinguished from mere access authorization by its forward-looking, descriptive quality: it captures *what the system is being used for* by a given account holder—mission function, business role, data types handled—not simply *whether* access is permitted. In access-control and account-management practice, access to a system is granted based on a valid access authorization, *intended system usage*, and other attributes required by the organization or associated missions/business functions. Correspondingly, account managers must be notified when *system usage* or need-to-know changes for an individual, making it a live attribute that is re-evaluated throughout the account lifecycle, not just at onboarding.DR-088 backfill from the noun definition column