System Administrator
A system administrator is the person responsible for setting up, configuring, and maintaining a computer system or specific parts of it, including its hardware, operating system, and applications. They keep systems running reliably by installing updates and managing day-to-day operations. In practice, responsibilities can vary considerably depending on the organization and how job titles are defined.
A system administrator (SA) is a person who manages a computer system, including its operating system and applications, and is generally responsible for the upkeep, configuration, and reliable operation of that system or its designated components (for example, installing, configuring, and updating hardware and software). Per CISA's work-role framing, the SA is accountable for setting up and maintaining a system or specific system components; NIST's CSRC glossary similarly scopes the role to management of a computer system, its operating system, and applications. The precise duties, privilege levels, and boundaries of an SA role are typically defined by organizational policy and system security plans, and readers should confirm role-specific requirements against the applicable authorization documentation and current official sources.
Why it matters
The system administrator role sits at the center of an organization's day-to-day technical operations, which makes it a focal point for both security and compliance. Because SAs generally hold elevated privileges to install, configure, and update hardware, operating systems, and applications, their accounts and actions carry outsized risk: a misconfiguration, a missed update, or the compromise of an administrator credential can undermine the confidentiality, integrity, or availability of an entire system. In defense and federal environments, this is why privileged roles like the SA are typically subject to specific access controls, accountability requirements, and monitoring defined in a system's authorization documentation.
For compliance purposes, the SA is one of the roles most often called out in a system security plan because so many control families depend on how administrative privileges are provisioned, separated, and audited. Duties, privilege levels, and boundaries vary considerably across organizations, so an SA in one environment may carry responsibilities that another organization splits across several roles. This variability is itself a compliance concern: authorizing officials and assessors generally expect the actual duties and access of an SA to match what is documented, rather than relying on job titles alone.
A common expert correction is that holding the SA title does not, by itself, establish what an individual is authorized to do. Access and privilege are governed by organizational policy and the applicable security plan, not by the label. Readers should confirm role-specific requirements, privilege boundaries, and accountability expectations against the current authorization documentation and official sources rather than assuming a standard, uniform SA definition applies everywhere.
Who it's relevant to
Inside SA
Common questions
Answers to the questions practitioners most commonly ask about SA.