The basis of this kind of security is that an individual user, or program operating on the user's behalf, is allowed to specify explicitly the types of access other users (or programs executing on their behalf) may have to information under the user's control. (FIPS 191) (NISTIR) A means of restricting access to objects (e.g., files, data entities) based on the identity and need-to-know of subjects (e.g., users, processes) and/or groups to which the object belongs. The controls are discretionary in the sense that a subject with a certain access permission is capable of passing that permission (perhaps indirectly) on to any other subject (unless restrained by mandatory access control). (CNSSI-4009) (NISTIR)
Understand more election terms clearly
Get one important election term explained each week, with authoritative sources, practical context and related definitions.
The basis of this kind of security is that an individual user, or program operating on the user's behalf, is allowed to specify explicitly the types of access other users (or programs executing on their behalf) may have to information under the user's control. (FIPS 191) (NISTIR) A means of restricting access to objects (e.g., files, data entities) based on the identity and need-to-know of subjects (e.g., users, processes) and/or groups to which the object belongs. The controls are discretionary in the sense that a subject with a certain access permission is capable of passing that permission (perhaps indirectly) on to any other subject (unless restrained by mandatory access control). (CNSSI-4009) (NISTIR)
Cite this term
Election Security Glossary. (2026). Discretionary Access Control. In Election Security Glossary. Retrieved August 20, 2026, from https://electionsecurityglossary.com/glossary/discretionary-access-control
Sources
01
Single-source
Get the weekly election term
Receive one cited, source-backed election explanation in your inbox each week.