organization-defined security-relevant information
A parameterized placeholder used in NIST SP 800-53 access-control statements, combining the standard `[Assignment: organization-defined …]` tailoring syntax with the defined term "security-relevant information" — information within a system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data. The full expression does not coin a new concept; it instructs each organization to enumerate, from that category, the specific assets it will protect — such as filtering rules for routers/firewalls, cryptographic key management information, configuration parameters for security services, and access control lists. In practice it appears in control AC-3(5), where the information system prevents access to `[Assignment: organization-defined security-relevant information]` except during secure, non-operable system states, leaving the exact scope of that information for each organization to specify in its System Security Plan.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A parameterized placeholder used in NIST SP 800-53 access-control statements, combining the standard `[Assignment: organization-defined …]` tailoring syntax with the defined term "security-relevant information" — information within a system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data. The full expression does not coin a new concept; it instructs each organization to enumerate, from that category, the specific assets it will protect — such as filtering rules for routers/firewalls, cryptographic key management information, configuration parameters for security services, and access control lists. In practice it appears in control AC-3(5), where the information system prevents access to `[Assignment: organization-defined security-relevant information]` except during secure, non-operable system states, leaving the exact scope of that information for each organization to specify in its System Security Plan.DR-088 backfill from the noun definition column