organization-defined types of cryptography
An organization-defined parameter (ODP) placeholder used in risk-based security control frameworks — specifically in NIST SP 800-53 control SC-13 (Cryptographic Protection) and its derivatives such as SP 800-171 — that an organization is required to populate with the specific cryptographic mechanisms, standards, or algorithms it has selected for each designated cryptographic use case. ODPs of this kind are included in certain security requirements to provide flexibility through assignment and selection operations, allowing organizations to specify values tailored to their specific protection needs. In practice, it pairs with a companion ODP for "organization-defined cryptographic uses," so that for each use case an organization names, it must also designate the corresponding type of cryptography to implement. Acceptable values are drawn from applicable standards: generally applicable cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography; for example, organizations protecting classified information may specify the use of NSA-approved cryptography.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- organization-defined types of cryptographies
- possessive
- organization-defined types of cryptography's
- pluralpossessive
- organization-defined types of cryptographies'