access control
Term · Cybersecurity · MLC-T-CYB-000032
1. The process of granting or denying specific requests to 1) obtain and use information and related information processing services and 2) enter specific physical facilities (e.g., federal buildings, military establishments, border crossing entrances).
2. The decision to permit or deny a subject access to system objects (network, data, application, service, etc.)
3. To ensure that an entity can only access protected resources if they have the appropriate permissions based on the predefined access control policies.
4. The right or a permission that is granted to a system entity to access a system resource.
5. The official management decision given by a senior organizational official to authorize the operation of an information system and to explicitly accept the risk to organizational operations and assets, individuals, other organizations, and the Nation, based on the implementation of an agreed-upon set of security controls.
6. Access privileges granted to a user, program, or process or the act of granting those privileges. Formerly known as "accreditation."
7. The decision to permit or deny a subject access to system objects (network, data, application, service, etc.).
8. The process of granting or denying specific requests to: 1) obtain and use information and related information processing services; and 2) enter specific physical facilities (e.g., federal buildings, military establishments, border crossing entrances).
9. Access privileges granted to a user, program, or process or the act of granting those privileges.
10. The process of permitting or restricting access to applications at a granular level, such as per-user, per-group, and per-resources.
11. Procedures and controls that limit or detect access to critical information resources. This can be accomplished through software, biometrics devices, or physical access to a controlled space.
12. The granting or denying of access rights to a user, program, or process.
13. Enable authorized use of a resource while preventing unauthorized use or use in an unauthorized manner.
14. Process of granting access to information system resources only to authorized users, programs, processes, or other systems.
15. The process of granting access to information technology (IT) system resources only to authorized users, programs, processes, or other systems.
16. Restricts resource access to only privileged entities.
17. Restricts access to resources only to privileged entities.
18. The process of granting or denying specific requests to: (i) obtain and use information and related information processing services; and (ii) enter specific physical facilities (e.g., Federal buildings, military establishments, and border-crossing entrances).
19. As used in this Recommendation, the set of procedures and/or processes that only allow access to information in accordance with pre-established policies and rules.
20. Restricts resource access to only authorized entities.
21. The process of granting or denying specific requests for obtaining and using information and related information processing services; and to enter specific physical facilities (e.g., Federal buildings, military establishments, and border crossing entrances).
22. The process of limiting access to resources of a system only to authorized programs, processes, or other systems (in a network).
23. The process of granting or denying specific requests for obtaining and using information and related information processing services.
24. The process of granting or denying specific requests: 1) obtain and use information and related information processing services; and 2) enter specific physical facilities (e.g., Federal buildings, military establishments, border crossing entrances).
25. Restricts access to resources to only privileged entities.
| Identifier | MLC-T-CYB-000032 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | AC |
| Synonyms | authorization |
| References | FIPS 201-3; NIST SP 800-162; NISTIR 7497; NIST SP 800-82r3 from RFC 4949 (adapted); NIST SP 800-175A; CNSSI 4009-2022 from NIST SP 800-63-3 (adapted); CNSSI 4009-2022 from NIST SP 800-162 (adapted); NIST SP 800-12 Rev. 1 from FIPS 201-2; NIST SP 1800-25B from FIPS 201-2, CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 1800-26B from FIPS 201-2, CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 1800-10B from FIPS 201-2, CNSSI 4009-2015, CNSSI 4009-2022; CNSSI 4009-2015; NIST SP 800-53 Rev. 5 from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-160 Vol. 2 Rev. 1 from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-53A Rev. 5 from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-113; NIST SP 800-192; NISTIR 7316; NIST SP 800-33 [Withdrawn]; NIST SP 800-27 Rev. A [Withdrawn]; NIST SP 800-32 [Withdrawn]; NIST SP 800-47 [Superseded]; NIST SP 800-57 Part 1 Rev. 4 [Superseded]; NIST SP 800-57 Part 2 [Superseded]; NIST SP 800-79-2; NIST SP 800-57 Part 2 Rev.1; NIST SP 800-57 Part 1 Rev. 5; NIST SP 800-53 Rev. 5 from FIPS 201-2; NISTIR 4734; NISTIR 7711; FIPS 201 [version unknown]; NIST SP 800-57 Part 1 Rev. 3 [Superseded]; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-000032",
"term": "access control",
"field": "Cybersecurity",
"definition": "1. The process of granting or denying specific requests to 1) obtain and use information and related information processing services and 2) enter specific physical facilities (e.g., federal buildings, military establishments, border crossing entrances).\n\n2. The decision to permit or deny a subject access to system objects (network, data, application, service, etc.)\n\n3. To ensure that an entity can only access protected resources if they have the appropriate permissions based on the predefined access control policies.\n\n4. The right or a permission that is granted to a system entity to access a system resource.\n\n5. The official management decision given by a senior organizational official to authorize the operation of an information system and to explicitly accept the risk to organizational operations and assets, individuals, other organizations, and the Nation, based on the implementation of an agreed-upon set of security controls.\n\n6. Access privileges granted to a user, program, or process or the act of granting those privileges. Formerly known as \"accreditation.\"\n\n7. The decision to permit or deny a subject access to system objects (network, data, application, service, etc.).\n\n8. The process of granting or denying specific requests to: 1) obtain and use information and related information processing services; and 2) enter specific physical facilities (e.g., federal buildings, military establishments, border crossing entrances).\n\n9. Access privileges granted to a user, program, or process or the act of granting those privileges.\n\n10. The process of permitting or restricting access to applications at a granular level, such as per-user, per-group, and per-resources.\n\n11. Procedures and controls that limit or detect access to critical information resources. This can be accomplished through software, biometrics devices, or physical access to a controlled space.\n\n12. The granting or denying of access rights to a user, program, or process.\n\n13. Enable authorized use of a resource while preventing unauthorized use or use in an unauthorized manner.\n\n14. Process of granting access to information system resources only to authorized users, programs, processes, or other systems.\n\n15. The process of granting access to information technology (IT) system resources only to authorized users, programs, processes, or other systems.\n\n16. Restricts resource access to only privileged entities.\n\n17. Restricts access to resources only to privileged entities.\n\n18. The process of granting or denying specific requests to: (i) obtain and use information and related information processing services; and (ii) enter specific physical facilities (e.g., Federal buildings, military establishments, and border-crossing entrances).\n\n19. As used in this Recommendation, the set of procedures and/or processes that only allow access to information in accordance with pre-established policies and rules.\n\n20. Restricts resource access to only authorized entities.\n\n21. The process of granting or denying specific requests for obtaining and using information and related information processing services; and to enter specific physical facilities (e.g., Federal buildings, military establishments, and border crossing entrances).\n\n22. The process of limiting access to resources of a system only to authorized programs, processes, or other systems (in a network).\n\n23. The process of granting or denying specific requests for obtaining and using information and related information processing services.\n\n24. The process of granting or denying specific requests: 1) obtain and use information and related information processing services; and 2) enter specific physical facilities (e.g., Federal buildings, military establishments, border crossing entrances).\n\n25. Restricts access to resources to only privileged entities.",
"abbreviation": "AC",
"synonyms": [
"authorization"
],
"references": [
"FIPS 201-3",
"NIST SP 800-162",
"NISTIR 7497",
"NIST SP 800-82r3 from RFC 4949 (adapted)",
"NIST SP 800-175A",
"CNSSI 4009-2022 from NIST SP 800-63-3 (adapted)",
"CNSSI 4009-2022 from NIST SP 800-162 (adapted)",
"NIST SP 800-12 Rev. 1 from FIPS 201-2; NIST SP 1800-25B from FIPS 201-2, CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 1800-26B from FIPS 201-2, CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 1800-10B from FIPS 201-2, CNSSI 4009-2015, CNSSI 4009-2022",
"CNSSI 4009-2015; NIST SP 800-53 Rev. 5 from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-160 Vol. 2 Rev. 1 from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-53A Rev. 5 from CNSSI 4009-2015, CNSSI 4009-2022",
"NIST SP 800-113",
"NIST SP 800-192; NISTIR 7316",
"NIST SP 800-33 [Withdrawn]; NIST SP 800-27 Rev. A [Withdrawn]",
"NIST SP 800-32 [Withdrawn]",
"NIST SP 800-47 [Superseded]",
"NIST SP 800-57 Part 1 Rev. 4 [Superseded]",
"NIST SP 800-57 Part 2 [Superseded]",
"NIST SP 800-79-2",
"NIST SP 800-57 Part 2 Rev.1",
"NIST SP 800-57 Part 1 Rev. 5",
"NIST SP 800-53 Rev. 5 from FIPS 201-2",
"NISTIR 4734",
"NISTIR 7711",
"FIPS 201 [version unknown]",
"NIST SP 800-57 Part 1 Rev. 3 [Superseded]",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/access-control/"
}
Record 32 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.