Meta tags:
Headings (most frequently used words):
authorization, contents, overview, implementation, related, interpretations, see, also, references, public, policy, banking, publishing,
Text of the page (most frequently used words):
the (36), #authorization (31), access (30), and (22), security (20), control (15), computer (12), for (12), edit (12), policy (10), information (9), management (8), wikipedia (7), with (7), from (7), system (7), authentication (7), resources (7), code (6), related (6), data (6), software (6), are (6), often (6), user (6), site (5), page (5), web (5), identity (5), applications (5), see (5), without (5), contents (4), search (4), this (4), application (4), owasp (4), systems (4), public (4), which (4), account (4), where (4), consumers (4), they (4), authorized (4), hide (4), move (4), sidebar (4), toggle (3), view (3), privacy (3), may (3), using (3), was (3), articles (3), authority (3), retrieved (3), org (3), rights (3), detection (3), based (3), secure (3), hardware (3), social (3), privilege (3), history (3), party (3), other (3), publishing (3), banking (3), used (3), interpretations (3), not (3), one (3), more (3), that (3), examples (3), include (3), here (3), tools (3), main (3), languages (2), table (2), mobile (2), contact (2), about (2), available (2), terms (2), use (2), march (2), categories (2), unsourced (2), statements (2), 2021 (2), 2023 (2), short (2), description (2), wikidata (2), international (2), protection (2), internet (2), warfare (2), fraud (2), risk (2), intrusion (2), multi (2), version (2), injection (2), trojans (2), email (2), download (2), cross (2), backdoors (2), 2007 (2), modern (2), 2025 (2), broken (2), top (2), 2017 (2), definition (2), references (2), xacml (2), openid (2), oauth (2), hold (2), free (2), also (2), lectures (2), texts (2), published (2), unauthorized (2), example (2), per (2), when (2), card (2), trusted (2), through (2), credentials (2), corresponding (2), third (2), widely (2), defined (2), subjects (2), roles (2), then (2), resource (2), has (2), been (2), least (2), limited (2), their (2), implementation (2), have (2), grant (2), should (2), only (2), such (2), domain (2), configuration (2), phase (2), iam (2), overview (2), what (2), deciding (2), whether (2), function (2), specifying (2), privileges (2), accessing (2), particular (2), human (2), item (2), authorisation (2), redirects (2), appearance (2), upload (2), file (2), changes (2), links (2), read (2), article (2), log (2), create (2), donate (2), menu (2), add, topic, cookie, statement, statistics, developers, conduct, legal, safety, contacts, disclaimers, text, under, additional, apply, you, agree, registered, trademark, non, profit, organization, wikimedia, foundation, inc, creative, commons, attribution, sharealike, license, rendered, parsoid, last, edited, 2026, utc, hidden, august, all, dmy, dates, matches, https, index, php, title, oldid, 1341431660, czech, republic, national, gnd, databases, digital, copy, network, electronic, cyberwarfare, cyberterrorism, cybergeddon, cybersex, trafficking, cybercrime, automotive, topics, scrubber, center, isolation, runtime, self, siem, event, anomaly, hids, host, firewall, encryption, masking, obfuscation, centric, focused, operating, antivirus, factor, misuse, case, design, default, coding, defenses, vectorial, zombie, rogue, sql, worms, wiper, shells, vulnerability, remote, trojan, horses, bugs, spyware, engineering, spamming, shellcode, scareware, rootkits, ransomware, escalation, polymorphic, engine, voice, phishing, payload, malware, keystroke, loggers, insecure, direct, object, reference, infostealer, hacktivism, fraudulent, dialers, exploits, spoofing, eavesdropping, denial, service, attack, scraping, viruses, browser, helper, objects, drive, breach, botnets, cryptojacking, sniffing, dom, clobbering, leaks, scripting, crimeware, bombs, zip, time, logic, fork, arbitrary, execution, advanced, persistent, threat, adware, threats, gates, carrie, ieee, requirements, hingnikar, abhishek, 2nd, 147, 9781484282601, isbn, apress, solving, cheatsheetseries, cheat, sheet, series, a01, jøsang, audun, proceedings, 13th, workshop, trust, stm, consistent, fraser, 1997, ietf, rfc, 2196, handbook, webid, webfinger, usability, connect, kerberos, protocol, osid, look, wiktionary, dictionary, sometimes, freely, approval, these, called, 2002, collected, his, permission, copyright, law, citation, needed, stephen, hawking, theory, everything, origin, fate, universe, author, further, biography, official, adjective, placed, customer, purchase, made, credit, debit, feature, even, controlled, combination, problems, maintaining, trivial, represents, much, administrative, burden, managing, necessary, change, remove, done, changing, deleting, rules, alternative, securely, distributes, atomic, lists, model, rbac, granting, checking, being, accessed, assigned, those, however, rise, media, gaining, prominence, relationship, role, framework, authorizing, provides, standardized, way, obtain, exposing, anonymous, guests, required, authenticate, distributed, desirable, requiring, unique, familiar, keys, certificates, tickets, proving, tokens, listed, number, basis, whatever, need, jobs, nothing, principle, responsibility, department, manager, within, but, delegated, custodian, administrator, authorizations, expressed, policies, some, types, form, administration, point, capability, list, consists, following, two, phases, created, its, usage, takes, place, followed, ensure, consumer, gets, hence, relies, specified, during, networks, confused, process, verifying, someone, closely, enforces, requests, shall, approved, granted, disapproved, rejected, authenticated, most, cases, users, individual, files, functionality, provided, accounts, staff, typically, configured, employee, records, devices, programs, subject, spelling, differences, allowing, name, transfers, auth, epsom, derby, winner, horse, redirected, encyclopedia, projects, printable, pdf, print, export, switch, legacy, parser, get, shortened, url, cite, permanent, link, general, actions, english, talk, українська, türkçe, svenska, српски, srpski, shqip, русский, română, português, polski, norsk, bokmål, nederlands, മലയാളം, latviešu, кыргызча, 한국어, қазақша, qaraqalpaqsha, 日本語, italiano, ido, bahasa, indonesia, galego, français, suomi, فارسی, eesti, español, ελληνικά, deutsch, čeština, کوردی, azərbaycanca, العربية, subsection, personal, special, pages, recent, community, portal, learn, help, contribute, random, current, events, navigation, jump, content,
Text of the page (random words):
authorization wikipedia jump to content main menu main menu move to sidebar hide navigation main page contents current events random article about wikipedia contact us contribute help learn to edit community portal recent changes upload file special pages search search appearance donate create account log in personal tools donate create account log in contents move to sidebar hide top 1 overview 2 implementation 3 related interpretations toggle related interpretations subsection 3 1 public policy 3 2 banking 3 3 publishing 4 see also 5 references toggle the table of contents authorization 35 languages العربية azərbaycanca کوردی čeština deutsch ελληνικά español eesti فارسی suomi français galego bahasa indonesia ido italiano 日本語 qaraqalpaqsha қазақша 한국어 кыргызча latviešu മലയാളം nederlands norsk bokmål polski português română русский shqip српски srpski svenska türkçe українська 粵語 中文 edit links article talk english read edit view history tools tools move to sidebar hide actions read edit view history general what links here related changes upload file permanent link page information cite this page get shortened url switch to legacy parser print export download as pdf printable version in other projects wikidata item appearance move to sidebar hide from wikipedia the free encyclopedia redirected from authorisation function of specifying access rights and privileges to resources authorized redirects here for the 2007 epsom derby winner see authorized horse authorization code redirects here for the code allowing internet domain name transfers see auth code authorization or authorisation see spelling differences in information security computer security and iam identity and access management 1 is the function of specifying rights privileges for accessing resources in most cases through an access policy and then deciding whether a particular subject has privilege to access a particular resource examples of subjects include human users computer software and other hardware on the computer examples of resources include individual files or an item s data computer programs computer devices and functionality provided by computer applications for example user accounts for human resources staff are typically configured with authorization for accessing employee records authorization is closely related to access control which is what enforces the authorization policy by deciding whether access requests to resources from authenticated consumers shall be approved granted or disapproved rejected 2 authorization should not be confused with authentication which is the process of verifying someone s identity overview edit iam consists the following two phases the configuration phase where a user account is created and its corresponding access authorization policy is defined and the usage phase where user authentication takes place followed by access control to ensure that the user consumer only gets access to resources for which they are authorized hence access control in computer systems and networks relies on access authorization specified during configuration authorization is the responsibility of an authority such as a department manager within the application domain but is often delegated to a custodian such as a system administrator authorizations are expressed as access policies in some types of policy definition application e g in the form of an access control list or a capability or a policy administration point e g xacml broken authorization is often listed as the number one risk in web applications 3 on the basis of the principle of least privilege consumers should only be authorized to access whatever they need to do their jobs and nothing more 4 anonymous consumers or guests are consumers that have not been required to authenticate they often have limited authorization on a distributed system it is often desirable to grant access without requiring a unique identity familiar examples of access tokens include keys certificates and tickets they grant access without proving identity implementation edit a widely used framework for authorizing applications is oauth 2 it provides a standardized way for third party applications to obtain limited access to a user s resources without exposing their credentials 5 in modern systems a widely used model for authorization is role based access control rbac where authorization is defined by granting subjects one or more roles and then checking that the resource being accessed has been assigned at least one of those roles 5 however with the rise of social media relationship based access control is gaining more prominence 6 even when access is controlled through a combination of authentication and access control lists the problems of maintaining the authorization data is not trivial and often represents as much administrative burden as managing authentication credentials it is often necessary to change or remove a user s authorization this is done by changing or deleting the corresponding access rules on the system using atomic authorization is an alternative to per system authorization management where a trusted third party securely distributes authorization information related interpretations edit public policy edit in public policy authorization is a feature of trusted systems used for security or social control banking edit in banking an authorization is a hold placed on a customer s account when a purchase is made using a debit card or credit card publishing edit further information official adjective and unauthorized biography in publishing sometimes public lectures and other freely available texts are published without the approval of the author these are called unauthorized texts an example is the 2002 the theory of everything the origin and fate of the universe which was collected from stephen hawking s lectures and published without his permission as per copyright law citation needed see also edit look up authorization in wiktionary the free dictionary access control authorization hold authorization osid kerberos protocol multi party authorization oauth openid connect openid usability of web authentication systems webfinger webid xacml references edit fraser b 1997 rfc 2196 site security handbook ietf jøsang audun 2017 a consistent definition of authorization proceedings of the 13th international workshop on security and trust management stm 2017 a01 broken access control owasp top 10 2021 owasp org retrieved 1 may 2025 authorization owasp cheat sheet series cheatsheetseries owasp org retrieved 1 may 2025 1 2 hingnikar abhishek 2023 solving identity management in modern applications 2nd ed apress pp 63 147 isbn 9781484282601 gates carrie 2007 access control requirements for web 2 0 security and privacy ieee web 2 12 15 v t e information security threats adware advanced persistent threat arbitrary code execution backdoors bombs fork logic time zip hardware backdoors code injection crimeware cross site scripting cross site leaks dom clobbering history sniffing cryptojacking botnets data breach drive by download browser helper objects viruses data scraping denial of service attack eavesdropping email fraud email spoofing exploits fraudulent dialers hacktivism infostealer insecure direct object reference keystroke loggers malware payload phishing voice polymorphic engine privilege escalation ransomware rootkits scareware shellcode spamming social engineering spyware software bugs trojan horses hardware trojans remote access trojans vulnerability web shells wiper worms sql injection rogue security software zombie vectorial version defenses application security secure coding secure by default secure by design misuse case computer access control authentication multi factor authentication authorization computer security software antivirus software security focused operating system data centric security software obfuscation data masking encryption firewall intrusion detection system host based intrusion detection system hids anomaly detection information security management information risk management security information and event management siem runtime application self protection site isolation scrubber center related security topics computer security automotive security cybercrime cybersex trafficking computer fraud cybergeddon cyberterrorism cyberwarfare electronic warfare information warfare internet security mobile security network security copy protection digital rights management authority control databases international gnd national czech republic retrieved from https en wikipedia org w index php title authorization oldid 1341431660 categories computer access control access control authority hidden categories articles with short description short description matches wikidata use dmy dates from march 2023 all articles with unsourced statements articles with unsourced statements from august 2021 this page was last edited on 3 march 2026 at 04 59 utc page was rendered with parsoid text is available under the creative commons attribution sharealike 4 0 license additional terms may apply by using this site you agree to the terms of use and privacy policy wikipedia is a registered trademark of the wikimedia foundation inc a non profit organization privacy policy about wikipedia disclaimers contact wikipedia legal safety contacts code of conduct developers statistics cookie statement mobile view search search toggle the table of contents authorization 35 languages add topic
|