home/glossary/organization-defined frequency

organization-defined frequency

nounverified·updated Sep 1, 2026

An *organization-defined frequency* is an instance of an **organization-defined control parameter** — the variable part of a security or privacy control that an organization fills in during the tailoring process by assigning a concrete value. As a frequency parameter specifically, it is a placeholder in a control statement that requires the implementing organization to decide *how often* a required activity — such as a review, update, assessment, or report — must recur, calibrating the cadence to the organization's own risk environment, mission, and operational tempo rather than prescribing a universal interval. The rationale is that circumstances such as organizational missions, business functions, environments of operation, technologies, or threat change over time, making periodic repetition of certain activities necessary and the appropriate interval something each organization must judge for itself. In practice, it appears throughout NIST control catalogs as an *Assignment* notation — e.g., `[Assignment: organization-defined frequency]` — wherever a control mandates a recurring action and leaves the interval open for the organization to specify, with implementers then documenti

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 24 citations in that document; a definition is pending curation.

Classifications

Entity Type

Requirement85%manual reviewllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
organization-defined frequencies
possessive
organization-defined frequency's
pluralpossessive
organization-defined frequencies'