Access Control — Election Security Glossary
115 election security terms in the Access Control category, with definitions sourced from NIST, CISA, EAC, and 30+ authoritative documents.
Browse all 115 terms in Access Control
Anti Spoof
Countermeasures taken to prevent the unauthorized use of legitimate identification & authentication (I&A) data, however it was obtained, to mimic a subject different from the…
Attribute Based Authorization
A structured process that determines when a user is authorized to access information, systems, or services based on attributes of the user and of the information, system, or…
Authentication Mechanism
Hardware or software-based mechanisms that force users to prove their identity before accessing data on a device.
Authentication Period
The period between any initial authentication process and subsequent re-authentication processes during a single terminal session or during the period data is being accessed.
Authentication Protocol
1. A well specified message exchange process between a claimant and a verifier that enables the verifier to confirm the claimant's identity.
Authenticator
The means used to confirm the identity of a user, process, or device (e.g., user password or token).
Authorize Processing
See authorization. Source: NIST SP 800-53 Rev 4; NIST SP 800-37 Rev 1.
Biometrics
Measurable physical characteristics or personal behavioral traits used to identify, or verify the claimed identity, of an individual.
Blacklisting
The process used to identify: (i) software programs that are not authorized to execute on an information system; or (ii) prohibited universal resource locators (URL)/websites.
Call Back
Procedure for identifying and authenticating a remote information system terminal, whereby the host system disconnects the terminal and reestablishes contact.
Challenge And Reply Authentication
Prearranged procedure in which a subject requests authentication of another and the latter establishes validity with a correct reply.
Claimant
A party whose identity is to be verified using an authentication protocol.
By ESG Editorial Team · Drawing on NIST SP 800-53, CISA, EAC, and 30+ authoritative sources on election security
Access control governs who can reach election systems, what they can do once inside, and under what circumstances their access is logged, reviewed, or revoked. The scope is broad. It covers the county employee logging into a voter registration database, the vendor technician uploading firmware to a tabulation machine, the poll worker opening a ballot bag on election morning, and the remote auditor connecting to a results-reporting portal from a home office.
Why this category matters for election security begins with a simple observation. Most successful intrusions, both in commercial cybersecurity and in documented election-administration incidents, have started with credentials. An attacker who has a valid username and password, or who has persuaded a user to hand one over, often bypasses the most sophisticated perimeter defenses. The controls that limit who has access, that verify the identity of users at the moment of access, and that log what they did are therefore not optional extras but core infrastructure.
In election administration, access control is shaped by a mix of federal expectations and state implementation. The Election Assistance Commission publishes voluntary guidance, the Cybersecurity and Infrastructure Security Agency issues advisories, and individual states layer their own requirements on top. What results is a landscape where the controls in place in a small county office may be very different from those in a state-level system, even when both are designed to protect the same kind of asset.
The terminology in this category reflects both the principles (least privilege, separation of duties, multi-factor authentication) and the practical realities (shared accounts during election night, vendor access for routine maintenance, federated identity for cross-jurisdiction data exchange). The concepts here are not abstract. They describe what happens at the door.
Key Concepts
Access Control
The set of policies and mechanisms that determine who can reach election systems and what they can do there.
Multi Factor Authentication
An authentication method requiring two or more independent factors, reducing the impact of stolen passwords.
Role Based Access Control
A model in which access permissions are assigned to roles (e.g. precinct manager) rather than to individual users.
How These Terms Relate
These concepts together describe the layered controls that protect election systems from unauthorized use. Access control is the policy framework. Multi-factor authentication, role-based access, and least privilege are the technical mechanisms that enforce it. Physical controls and separation of duties extend the same principles to spaces and processes where software alone cannot reach. The goal is not to make intrusion impossible but to make it detectable, attributable, and constrained: an attacker who reaches one system should not be able to reach every system, and every action should leave a trail that auditors can review.
Related categories
1,851 terms
The wider cybersecurity context that access controls operate within.
Network Security37 terms
Network-level controls that complement application-level access rules.
Physical Security23 terms
Physical access controls that protect facilities housing election equipment.
Personnel1 terms
Staff training, background checks, and insider-threat programs that complement technical access controls.
Can't find the right category?
Search the full glossary, or browse every term alphabetically instead.