The official management decision given by a senior agency official to authorize operation of an information system and to explicitly accept the risk to agency operations (including mission, functions, image, or reputation), agency assets, or individuals, based on the implementation of an agreed-upon set of security controls.
NIST SP 800-18 Rev. 1
under Accreditation
NIST SP 800-60 Vol. 1 Rev. 1
under Accreditation
FIPS 200
The right or a permission that is granted to a system entity to access a system resource.
NIST SP 1800-10B
under Authorization
NIST SP 800-82r3
NIST SP 1800-27C
under Authorization
NIST SP 800-82r3
Access privileges granted to a user, program, or process or the act of granting those privileges.
CNSSI 4009-2015
under authorization
NIST SP 800-160 Vol. 2 Rev. 1
under authorization
CNSSI 4009-2015
NIST SP 800-53 Rev. 5
under authorization
CNSSI 4009-2015
NIST SP 800-53A Rev. 5
under authorization
CNSSI 4009-2015
The official management decision given by a senior official to authorize operation of a system or the common controls inherited by designated organizations systems and to explicitly accept the risk to organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation based on the implementation of an agreed-upon set of security and privacy controls. Also known as authorization to operate.
NIST SP 800-12 Rev. 1
under Authorization
The process of verifying that a requested action or service is approved for a specific entity.
NIST SP 800-152
under Authorization
NIST SP 800-57 Part 2 Rev.1
under Authorization
also known as authorize processing (OMB Circular A-130, Appendix III),and approval to operate. Accreditation (or authorization to process information) is granted by a management official and provides an important quality control. By accrediting a system or application, a manager accepts the associated risk. Accreditation (authorization) must be based on a review of controls. (See Certification.)
NIST SP 800-16
under Accreditation
See Accreditation.
NIST SP 800-18 Rev. 1
under Authorize Processing
Access privileges granted to an entity; conveys an “official” sanction to perform a cryptographic function or other sensitive activity.
NIST SP 800-57 Part 2 Rev.1
under Authorization
See authorization.
CNSSI 4009-2015
Access privileges that are granted to an entity that convey an “official” sanction to perform a security function or activity.
NIST SP 800-57 Part 1 Rev. 5
under Authorization
The official management decision of the Designated Authorizing Official to permit operation of an issuer after determining that the issuer’s reliability has satisfactorily been established through appropriate assessment processes.
NIST SP 800-79-2
under Authorization
The right or a permission that is granted to a system entity to access a system resource.
NIST SP 800-82r3
under authorization
RFC 4949 - adapted
The official management decision given by a senior organizational official to authorize the operation of an information system and to explicitly accept the risk to organizational operations and assets, individuals, other organizations, and the Nation, based on the implementation of an agreed-upon set of security controls.
NIST SP 800-175A
under authorization
The granting or denying of access rights to a user, program, or process.
under Authorization
The process of initially establishing access privileges of an individual and subsequently verifying the acceptability of a request for access.
under Authorization