Skip to content

Authorization

What is Authorization?

The process of determining whether a user, program, or device is permitted to access a resource, perform an operation, or execute a command.

Information Security

Each of these is named in at least one of the same controls as authorization. The number is how many controls name both.

What the standards actually require on authorization

Requirements naming authorization across 6 standards, quoted from the control text.

Requires an assessment, authorization and monitoring policy with supporting procedures to be developed, approved, disseminated to defined personnel, assigned to a named official, and reviewed and updated on a defined frequency and after defined events.

NIST800-CA-1 · Policy and procedures for assessment, authorization, and monitoring
FedRAMP High11 controls

Senior official authorizes system; reauthorize every three years or upon significant change.

CA-6 · Authorization
FedRAMP Rev 511 controls

STATERAMP + GovRAMP are FedRAMP-aligned authorization programs for state + local + tribal governments. STATERAMP (https://stateramp.org/) - non-profit organization + administers state-government cloud authorization mirroring FedRAMP processes + uses FedRAMP-co...

FedRAMP-StateRAMP-GovRAMP · Coordination with StateRAMP, GovRAMP and state + local + tribal government cloud authorization

Senior official authorizes system; reauthorize every three years or upon significant change.

CA-6 · Authorization

Develop, approve, and maintain list of individuals with authorized access to facility where CUI resides; issue credentials; review list periodically.

03.10.01 · Physical Access Authorizations

Processing requires prior, express and informed authorization of the data subject (except Art.10 cases), obtained by any means that can later be evidenced.

CO-L1581-A9 · Authorization of the Data Subject

Questions people ask about authorization

What is Authorization?
The process of determining whether a user, program, or device is permitted to access a resource, perform an operation, or execute a command.
Why is Authorization important for compliance?
Authorization is a key concept in Information Security. Understanding authorization helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Authorization?
Authorization appears in the requirement text of NIST SP 800-53 Rev 5, FedRAMP High, FedRAMP Rev 5, FedRAMP Moderate, NIST SP 800-171 Rev 3. Across these standards we have identified 60 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Authorization?
Explore our compliance framework pages to see how authorization applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Authorization applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.