Subject (access control)
The active entity in an access request, such as a user, process or device, that seeks to act on an object. The subject makes the request and the object is acted upon.
In access control, a subject is the active entity that requests access to a resource or acts on it: a user, a process running on the user’s behalf, a device, or a service account. The resource is the object, the passive entity that holds or receives information, such as a file, table or port. NIST SP 800-53 Rev. 5 draws the same line in its discussion of AC-16, describing subjects as active entities and objects as passive ones. Access decisions take the form of a subject performing an operation on an object, the structure behind the access control matrix and the reference monitor.
The roles belong to the interaction rather than to the thing. A program is an object while it sits on disk and is being updated, and a subject when it runs and opens files. Under mandatory access control, subjects carry a security clearance and objects a security label. The word has a neighbouring meaning in OpenID Connect, where the subject identifier is the stable, unique value an identity provider issues for a user.
Exam relevance: a scenario is likely to describe an interaction and ask which party is the subject. Candidates are expected to pick the active requester, and to recognise that the same entity can be an object in one interaction and a subject in another.