A mechanism that implements access control for a system resource by enumerating the identities of the system entities that are permitted to access the resources.
Sources:
NIST SP 800-82 Rev. 2
under Access Control List
from
RFC 4949
A list of entities, together with their access rights, that are authorized to have access to a resource.
Sources:
NISTIR 5153
under Access Control List
from
ISO DIS 10181-2