organizational system
An information system — comprising hardware, software, firmware, data, personnel, and associated facilities — that is owned, operated, or controlled by or on behalf of an organization and falls within that organization's authorization boundary and governance responsibility. It is the entity inside whose authorization boundary services and components reside, as distinct from external system services used by but not part of the system. In NIST's Risk Management Framework and related publications (SP 800-53 Rev. 5, SP 800-171 Rev. 3, SP 800-37 Rev. 2), the term serves as the consistent scope marker for applying security and privacy controls: organizations employ configuration settings, access controls, and other safeguards on the commercial IT products that compose their organizational systems. The controls in SP 800-53 are designed to protect organizational operations and assets through an organization-wide risk management process applied to these systems.
Senses
No definition is given in NIST SP 800-171r3. The term is attested in use at 9 citations in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- organizational systems
- possessive
- organizational system's
- pluralpossessive
- organizational systems'