home/dictionary/organization-defined security function

organization-defined security function

nounverified·updated Sep 1, 2026

** A placeholder construct used in control frameworks — most prominently NIST SP 800-53 and NIST SP 800-171 — where a security control statement is intentionally left partially open, requiring each implementing organization to enumerate the specific security-enforcing capabilities (hardware, software, or firmware mechanisms such as account management, access authorization configuration, audit-event settings, and intrusion-detection parameter management) that are subject to the control's requirement. It functions as an *assignment operation*: a control parameter that allows an organization to assign a specific, organization-defined value to the control or control enhancement. In practice, many NIST controls are not "complete" as published but require "fill in the blanks," and these blanks are called Organization-defined Values or Organization-defined Parameters; "organization-defined security functions" is one such parameter, naming whichever protective capabilities the organization determines fall under least-privilege or access-authorization scope — for example, establishing system accounts and assigning privileges, installing software, configuring access authorizations, configuri

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
** A placeholder construct used in control frameworks — most prominently NIST SP 800-53 and NIST SP 800-171 — where a security control statement is intentionally left partially open, requiring each implementing organization to enumerate the specific security-enforcing capabilities (hardware, software, or firmware mechanisms such as account management, access authorization configuration, audit-event settings, and intrusion-detection parameter management) that are subject to the control's requirement. It functions as an *assignment operation*: a control parameter that allows an organization to assign a specific, organization-defined value to the control or control enhancement. In practice, many NIST controls are not "complete" as published but require "fill in the blanks," and these blanks are called Organization-defined Values or Organization-defined Parameters; "organization-defined security functions" is one such parameter, naming whichever protective capabilities the organization determines fall under least-privilege or access-authorization scope — for example, establishing system accounts and assigning privileges, installing software, configuring access authorizations, configuri
DR-088 backfill from the noun definition column