A mechanism that implements access control for a system resource by enumerating the identities of the system entities that are permitted to access the resources.
Sources:
NIST SP 800-82r3
from
RFC 4949 - adapted
A list of entities, together with their access rights, that are authorized to have access to a resource.
Sources:
NISTIR 5153
under Access Control List
from
ISO DIS 10181-2