home/thesaurus/non-security function

non-security function

nounverified·updated Sep 1, 2026

A category of system capability or task — specifically, any operation, feature, or process whose purpose is ordinary business, user-productivity, or operational activity rather than the administration, enforcement, or configuration of security controls. In NIST SP 800-171 and related least-privilege frameworks, it serves as the contrast class to "security functions" (privileged operations such as modifying access policies, managing accounts, or configuring audit mechanisms), and the distinction drives the rule that elevated privileges must not be active during routine work. Practitioners use it to draw the boundary at which a privileged account or role must step down to a non-privileged one, limiting the blast radius of credential compromise or user error during everyday tasks.

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.