home/dictionary/expected inactivity

expected inactivity

nounverified·updated Aug 30, 2026

A compositional noun phrase used in access-control policy language to denote a period during which a user anticipates having no interaction with a system — distinguishable from *observed* or *detected* inactivity (which triggers automatic device-lock or session-termination mechanisms) in that it reflects the user's own foreknowledge or intent. NIST SP 800-53 AC-2(5) uses it to require that users log out when an organization-defined time period of expected inactivity applies, noting that this is behavior- or policy-based and requires users to take physical action to log out when they anticipate being inactive longer than a defined period. NIST SP 800-171A Rev. 3 similarly frames it as the condition after which users must log out, parameterized by an organization-defined time period. In practice the phrase qualifies an elapsed-time threshold or named circumstance that an organization plugs into its access-control policy; it does not name a discrete security object or procedure of its own.

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A compositional noun phrase used in access-control policy language to denote a period during which a user anticipates having no interaction with a system — distinguishable from *observed* or *detected* inactivity (which triggers automatic device-lock or session-termination mechanisms) in that it reflects the user's own foreknowledge or intent. NIST SP 800-53 AC-2(5) uses it to require that users log out when an organization-defined time period of expected inactivity applies, noting that this is behavior- or policy-based and requires users to take physical action to log out when they anticipate being inactive longer than a defined period. NIST SP 800-171A Rev. 3 similarly frames it as the condition after which users must log out, parameterized by an organization-defined time period. In practice the phrase qualifies an elapsed-time threshold or named circumstance that an organization plugs into its access-control policy; it does not name a discrete security object or procedure of its own.
DR-088 backfill from the noun definition column