home/glossary/organization-defined security-relevant information

organization-defined security-relevant information

nounverified·updated Sep 1, 2026

A parameterized placeholder used in NIST SP 800-53 access-control statements, combining the standard `[Assignment: organization-defined …]` tailoring syntax with the defined term "security-relevant information" — information within a system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data. The full expression does not coin a new concept; it instructs each organization to enumerate, from that category, the specific assets it will protect — such as filtering rules for routers/firewalls, cryptographic key management information, configuration parameters for security services, and access control lists. In practice it appears in control AC-3(5), where the information system prevents access to `[Assignment: organization-defined security-relevant information]` except during secure, non-operable system states, leaving the exact scope of that information for each organization to specify in its System Security Plan.

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.

Classifications

Entity Type

Requirement85%manual reviewllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

Regulated90%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Information Class

70%llm-generatedmulti_axis_classifier_queued.v1
?unassignedlast reviewed

Variants

plural
organization-defined security-relevant informations
possessive
organization-defined security-relevant information's
pluralpossessive
organization-defined security-relevant informations'