home/glossary/organization-defined security function

organization-defined security function

nounverified·updated Sep 1, 2026

** A placeholder construct used in control frameworks — most prominently NIST SP 800-53 and NIST SP 800-171 — where a security control statement is intentionally left partially open, requiring each implementing organization to enumerate the specific security-enforcing capabilities (hardware, software, or firmware mechanisms such as account management, access authorization configuration, audit-event settings, and intrusion-detection parameter management) that are subject to the control's requirement. It functions as an *assignment operation*: a control parameter that allows an organization to assign a specific, organization-defined value to the control or control enhancement. In practice, many NIST controls are not "complete" as published but require "fill in the blanks," and these blanks are called Organization-defined Values or Organization-defined Parameters; "organization-defined security functions" is one such parameter, naming whichever protective capabilities the organization determines fall under least-privilege or access-authorization scope — for example, establishing system accounts and assigning privileges, installing software, configuring access authorizations, configuri

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.

Classifications

Entity Type

Requirement85%manual reviewllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

Regulated90%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Information Class

70%llm-generatedmulti_axis_classifier_queued.v1
?unassignedlast reviewed

Variants

plural
organization-defined security functions
possessive
organization-defined security function's
pluralpossessive
organization-defined security functions'