home/dictionary/defined period

defined period

nounverified·updated Aug 30, 2026

A policy-established, organization-configurable duration of elapsed time—measured in minutes, hours, or days—that serves as a threshold triggering an automated security enforcement action when that duration expires without the expected activity. Across NIST SP 800-53/800-171, CIS Controls, PCI DSS, ISO/IEC 27001, and HIPAA, it functions as the configurable variable inside controls such as session locking, session termination, account disablement, and token expiry: the control specifies *that* enforcement must occur automatically, while the defined period is the organization-set value governing *when* it fires. It is intentionally left as a parameter rather than a fixed value in most frameworks because the appropriate threshold varies by asset type, data sensitivity, and risk posture—though regulators sometimes cap it (e.g., PCI DSS at 15 minutes for idle sessions, CIS Controls at 15 minutes for general-purpose OSes and 2 minutes for mobile devices).

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A policy-established, organization-configurable duration of elapsed time—measured in minutes, hours, or days—that serves as a threshold triggering an automated security enforcement action when that duration expires without the expected activity. Across NIST SP 800-53/800-171, CIS Controls, PCI DSS, ISO/IEC 27001, and HIPAA, it functions as the configurable variable inside controls such as session locking, session termination, account disablement, and token expiry: the control specifies *that* enforcement must occur automatically, while the defined period is the organization-set value governing *when* it fires. It is intentionally left as a parameter rather than a fixed value in most frameworks because the appropriate threshold varies by asset type, data sensitivity, and risk posture—though regulators sometimes cap it (e.g., PCI DSS at 15 minutes for idle sessions, CIS Controls at 15 minutes for general-purpose OSes and 2 minutes for mobile devices).
DR-088 backfill from the noun definition column