Table of Contents

Authorized Resource

Go to Terms and Definitions

Discussion

An Authorized Resource is a resource for which an identified actor or process has permission to perform one or more specified operations.

The resource may include:

Authorization applies within a defined context. The authorization may identify:

Permitted operations may include:

A resource does not become authorized merely because an actor can technically access it. Authorization requires permission granted through an applicable authority, policy, role, rule, or decision.

Definition

resource for which an identified actor or process has permission to perform specified operations under defined conditions

Source

Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

Note

Authorization may differ among actors, processes, operations, purposes, environments, and periods.

A resource authorized for reading is not necessarily authorized for modification, execution, transfer, or deletion.

Authorization does not by itself establish that the resource is:

Separate controls establish those characteristics.

Example

A deployment process has permission to retrieve an identified Machine Image from a designated repository and deploy it within a specified Infrastructure Environment. The Machine Image is an Authorized Resource for that process and deployment operation.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.