The IT Law Wiki

Definition[]

Discretionary access is

[t]he automated restricting of accesses to files, programs, protocols, resources, and information based on each user's need-to-know and least privilege requirement. Discretionary access uses either built in system security capabilities or "third party" security enhancement products.[1]

References[]

  1. USDA Information Systems Security Policy, §8(f) (full-text).