Category Overview

Access Control — Election Security Glossary

115 election security terms in the Access Control category, with definitions sourced from NIST, CISA, EAC, and 30+ authoritative documents.

Browse all 115 terms in Access Control

Privileged Command

A human-initiated command executed on an information system involving the control, monitoring, or administration of the system including security functions and associated…

Medium consensus2 sources

Privileged Process

A computer process that is authorized (and, therefore, trusted) to perform security- relevant functions that ordinary processes are not authorized to perform.

Medium consensus2 sources

Privileged User

A user that is authorized (and, therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform.

Medium consensus2 sources

Pseudonym

1. A subscriber name that has been chosen by the subscriber that is not verified as meaningful by identity proofing.

Medium consensus2 sources

Relying Party

An entity that relies on the validity of the binding of the Subscriber's name to a public key to verify or establish the identity and status of an individual, role, or system or…

Low consensus2 sources

Remote Access

Access to an organizational information system by a user (or a process acting on behalf of a user) communicating through an external network (e.g., the Internet).

Medium consensus2 sources

Role

A job function or employment position to which people or other system entities may be assigned in a system.

Low consensus2 sources

Ruleset

A table of instructions used by a controlled interface to determine what data is allowable and how the data is handled between interconnected systems.

Medium consensus2 sources

Secure State

Condition in which no subject can access any object in an unauthorized manner.

Medium consensus2 sources

Security Assertion Markup Language (saml)

A protocol consisting of XML-based request and response message formats for exchanging security information, expressed in the form of assertions about subjects, between on-line…

Medium consensus2 sources

Security Attribute

An abstraction representing the basic properties or characteristics of an entity with respect to safeguarding information; typically associated with internal data structures…

Medium consensus2 sources

Security Banner

1. A persistent visible window on a computer monitor that displays the highest level of data accessible during the current session.

Low consensus2 sources

By ESG Editorial Team · Drawing on NIST SP 800-53, CISA, EAC, and 30+ authoritative sources on election security

Access control governs who can reach election systems, what they can do once inside, and under what circumstances their access is logged, reviewed, or revoked. The scope is broad. It covers the county employee logging into a voter registration database, the vendor technician uploading firmware to a tabulation machine, the poll worker opening a ballot bag on election morning, and the remote auditor connecting to a results-reporting portal from a home office.

Why this category matters for election security begins with a simple observation. Most successful intrusions, both in commercial cybersecurity and in documented election-administration incidents, have started with credentials. An attacker who has a valid username and password, or who has persuaded a user to hand one over, often bypasses the most sophisticated perimeter defenses. The controls that limit who has access, that verify the identity of users at the moment of access, and that log what they did are therefore not optional extras but core infrastructure.

In election administration, access control is shaped by a mix of federal expectations and state implementation. The Election Assistance Commission publishes voluntary guidance, the Cybersecurity and Infrastructure Security Agency issues advisories, and individual states layer their own requirements on top. What results is a landscape where the controls in place in a small county office may be very different from those in a state-level system, even when both are designed to protect the same kind of asset.

The terminology in this category reflects both the principles (least privilege, separation of duties, multi-factor authentication) and the practical realities (shared accounts during election night, vendor access for routine maintenance, federated identity for cross-jurisdiction data exchange). The concepts here are not abstract. They describe what happens at the door.

How These Terms Relate

These concepts together describe the layered controls that protect election systems from unauthorized use. Access control is the policy framework. Multi-factor authentication, role-based access, and least privilege are the technical mechanisms that enforce it. Physical controls and separation of duties extend the same principles to spaces and processes where software alone cannot reach. The goal is not to make intrusion impossible but to make it detectable, attributable, and constrained: an attacker who reaches one system should not be able to reach every system, and every action should leave a trail that auditors can review.

Related categories

Can't find the right category?

Search the full glossary, or browse every term alphabetically instead.