Terminology Index
Glossary
2953 terms
A32
Authorization
Authorization is the decision about what an authenticated user, service, or system is allowed to do.
Good authorization limits access to the actions and data needed for the role and is reviewed when roles, ownership, or risk changes.
Introduced in: Security Foundations
Examples
- Admin-only action
- Read-only report access
Related
Authenticationrelates_toAttribute-Based Access Controlprerequisite_ofLeast Privilegerelates_toIdentificationrelates_toPBACrelates_toPermissionsrelates_toPoliciesrelates_toRBACrelates_toReBACrelates_toScopesrelates_toServer-Side Authorizationrelates_toVertical Privilege Escalationrelates_toAudit Trailrelates_to
