home/glossary/defined period

defined period

nounverified·updated Aug 30, 2026

A policy-established, organization-configurable duration of elapsed time—measured in minutes, hours, or days—that serves as a threshold triggering an automated security enforcement action when that duration expires without the expected activity. Across NIST SP 800-53/800-171, CIS Controls, PCI DSS, ISO/IEC 27001, and HIPAA, it functions as the configurable variable inside controls such as session locking, session termination, account disablement, and token expiry: the control specifies *that* enforcement must occur automatically, while the defined period is the organization-set value governing *when* it fires. It is intentionally left as a parameter rather than a fixed value in most frameworks because the appropriate threshold varies by asset type, data sensitivity, and risk posture—though regulators sometimes cap it (e.g., PCI DSS at 15 minutes for idle sessions, CIS Controls at 15 minutes for general-purpose OSes and 2 minutes for mobile devices).

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.

Classifications

Entity Type

Requirement88%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

Regulated90%rule-basedr:sens.regulated.framework.v1
?unassignedlast reviewed

Information Class

unclassified

Variants

plural
defined periods
possessive
defined period's
pluralpossessive
defined periods'