A process by which use of system resources is regulated according to a security policy and is permitted only by authorized entities (users, programs, processes, or other systems) according to that policy.(See: access, access control service, computer security, discretionary access control, mandatory access control, role-based access control.)