"Access privileges granted to a user, program, or process or the act of granting those privileges." (CNSSI 4009-2015)
"The granting or denying of access rights to a user, program, or process." (NIST SP 800-33)
[authorization to operate:] "The official management decision given by a senior official to authorize operation of a system or the common controls inherited by designated organizations systems and to explicitly accept the risk to organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security and privacy controls." (NIST SP 800-12 Rev. 1)
"The process of initially establishing access privileges of an individual and subsequently verifying the acceptability of a request for access." (NISTIR 4734)
"The process of verifying that a requested action or service is approved for a specific entity."(NIST SP 800-152)
"The right or a permission that is granted to a system entity to access a system resource."(NIST SP 800-82 Rev. 2)
No comments:
Post a Comment