Access Control List
Noun · Security & Infosec
Definitions
Access Control List is an authorization structure that stores ordered allow and deny entries for users, groups, or services on an object. Security teams use it to enforce trust, reduce exposure, improve detection, or standardize secure operations in production environments. Its value depends on correct configuration, lifecycle management, and surrounding controls, because weak defaults, poor integration, or missing visibility can create gaps that attackers exploit.
In plain English: Access Control List is a security concept or control that helps organizations protect systems, manage trust, and notice suspicious behavior before damage spreads.
Example: "After the review, the security team rolled out Access Control List in the affected environment, documented the operating procedure, and verified through logs and test cases that the control reduced exposure without breaking normal administrative or user workflows."
Related Terms
- Authorization
- Capability
- Active Directory
- Credential Manager
- Deauthentication Attack
- Default Credentials
- Just-in-Time Access
- Least Privilege
- Mandatory Access Control
- Role-Based Access Control
- Data Lake Security
- IDM
- Overprivileged
- PAM
- Permission Model
- Privileged Identity
- Read Access
- Role Engineering
- Role Explosion
- Role Mining