Glossary · MWE Terms · O
L1 — paginated flat list. Pick a POS, pick a letter.
TermTypeDefinitionClassificationsUpdated
Organ TransplantnounMWEan operation moving an organ from one organism (the donor) to another (the recipient)verified
Organic Brain SyndromenounMWEmental abnormality resulting from disturbance of the structure or function of the brainverified
Organic ChemistrynounMWEthe chemistry of compounds containing carbon (originally defined as the chemistry of substances produced by living organisms but now extended to substances synthesized artificially)verified
Organic DisordernounMWEdisorder caused by a detectable physiological or structural change in an organverified
Organic EvolutionnounMWE(biology) the sequence of events involved in the evolutionary development of a species or taxonomic group of organismsverified
Organic Light-Emitting DiodenounMWEa self-luminous diode (it glows when an electrical field is applied to the electrodes) that does not require backlighting or diffusersverified
Organic StructurenounMWEthe entire structure of an organism (an animal, plant, or human being)verified
Organization ChartnounMWEa chart showing the lines of responsibility between departments of a large organizationverified
Organization ExpensenounMWEthe cost (over a period of five years) of organizing a new corporation or partnershipverified
Organization MannounMWEan employee who sacrifices his own individuality for the good of an organizationverified
organization-defined circumstancenounMWEA structured placeholder — specifically an **assignment-operation parameter** — embedded in a security or privacy control statement, indicating that the implementing organization must supply a locally determined set of situational conditions under which the control action applies or is modified. It is the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list provided as part of the control or control enhancement. Concretely, the assignment operation allows an organization to assign a specific, organization-defined value to the control or control enhancement — for example, a list of roles to be notified or a value for the frequency of testing — and "circumstances" is simply the type of value the control author has left for the organization to fill in. Organization-defined parameters of this kind are used in SP 800-53 controls to provide flexibility to federal agencies in tailoring controls to support specific organizational missions or business functions and to manage risk.verified
organization-defined frequencynounMWEAn *organization-defined frequency* is an instance of an **organization-defined control parameter** — the variable part of a security or privacy control that an organization fills in during the tailoring process by assigning a concrete value. As a frequency parameter specifically, it is a placeholder in a control statement that requires the implementing organization to decide *how often* a required activity — such as a review, update, assessment, or report — must recur, calibrating the cadence to the organization's own risk environment, mission, and operational tempo rather than prescribing a universal interval. The rationale is that circumstances such as organizational missions, business functions, environments of operation, technologies, or threat change over time, making periodic repetition of certain activities necessary and the appropriate interval something each organization must judge for itself. In practice, it appears throughout NIST control catalogs as an *Assignment* notation — e.g., `[Assignment: organization-defined frequency]` — wherever a control mandates a recurring action and leaves the interval open for the organization to specify, with implementers then documentiverified
Organization-Defined ParameternounMWEThe variable part of a security requirement that is instantiated by an organization during the tailoring process by assigning an organization-defined value as part of the requirement. [8, adapted]verified
organization-defined personnelnounMWEAn organization-defined parameter (ODP) — specifically one whose value is a set of human recipients identified by job title, functional role, or organizational position — that an implementing organization must supply during the control-tailoring process to make a security or privacy control requirement complete and enforceable. It is the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list. Across NIST SP 800-53 and related frameworks, the assignment operation allows an organization to assign a specific, organization-defined value to the control — for example, assigning a list of roles to be notified. In practice the expression appears throughout policy-dissemination, notification, approval, and training controls — such as developing, documenting, and disseminating personnel security policy to [Assignment: organization-defined personnel or roles] or requiring third-party providers to notify [Assignment: organization-defined personnel or roles] of any personnel transfers or terminations — where each implementing organizationverified
organization-defined security functionnounMWE** A placeholder construct used in control frameworks — most prominently NIST SP 800-53 and NIST SP 800-171 — where a security control statement is intentionally left partially open, requiring each implementing organization to enumerate the specific security-enforcing capabilities (hardware, software, or firmware mechanisms such as account management, access authorization configuration, audit-event settings, and intrusion-detection parameter management) that are subject to the control's requirement. It functions as an *assignment operation*: a control parameter that allows an organization to assign a specific, organization-defined value to the control or control enhancement. In practice, many NIST controls are not "complete" as published but require "fill in the blanks," and these blanks are called Organization-defined Values or Organization-defined Parameters; "organization-defined security functions" is one such parameter, naming whichever protective capabilities the organization determines fall under least-privilege or access-authorization scope — for example, establishing system accounts and assigning privileges, installing software, configuring access authorizations, configuriverified
organization-defined security-relevant informationnounMWEA parameterized placeholder used in NIST SP 800-53 access-control statements, combining the standard `[Assignment: organization-defined …]` tailoring syntax with the defined term "security-relevant information" — information within a system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data. The full expression does not coin a new concept; it instructs each organization to enumerate, from that category, the specific assets it will protect — such as filtering rules for routers/firewalls, cryptographic key management information, configuration parameters for security services, and access control lists. In practice it appears in control AC-3(5), where the information system prevents access to `[Assignment: organization-defined security-relevant information]` except during secure, non-operable system states, leaving the exact scope of that information for each organization to specify in its System Security Plan.verified
organization-defined time periodnounMWEA placeholder variable embedded within a security or privacy control statement—a species of **organization-defined parameter (ODP)**—that reserves a duration value for the implementing organization to specify during the tailoring process. It is "the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list provided as part of the control or control enhancement." In practice, the standards body intentionally leaves the duration blank because the correct threshold differs by context, risk tolerance, and applicable regulatory constraints; organization-defined parameters are used in NIST SP 800-53 controls "to provide flexibility to federal agencies in tailoring controls to support specific organizational missions or business functions and to manage risk." Once filled in, the chosen value becomes part of the enforceable requirement and is subject to assessment: once ODPs have been defined, they become part of the security requirement and can be assessed as such, and they help simplify assessments by providing greater specificity andverified
Organizational Information Security Continuous MonitoringnounMWEOngoing monitoring sufficient to ensure and assure effectiveness of security controls related to systems, networks, and cyberspace, by assessing security control implementation and organizational security status in accordance with organizational risk tolerance – and within a reporting structure designed to make real-time, data-driven risk management decisions.verified
organizational personnelnounMWEThe aggregate of individuals who work within or on behalf of an organization and who hold duties, responsibilities, or roles that are relevant to the organization's security, privacy, or compliance posture. It is distinguished from narrower categories such as "security staff" or "privileged users" by its breadth: it spans every stratum and function—executives, system owners, administrators, auditors, and general users—while remaining bounded to those in the organizational trust relationship (as opposed to the general public or anonymous parties). In practice, standards and control frameworks use the expression as a recipient class for notifications, training, policy dissemination, and accountability requirements, often pairing it with "or roles" to allow organizations to address either named individuals or the positions they occupy.verified
organizational policynounMWEA formally documented set of management directives, issued at the enterprise or program level, that establishes the rules, constraints, roles, and responsibilities governing an organization's conduct in a given security or compliance domain. It sits at the top of the policy hierarchy—above issue-specific and system-specific policies—and is technology-agnostic, expressing *what* must be done rather than *how*; lower-level standards, guidelines, and procedures derive their authority from it. In practice, controls frameworks invoke it as the baseline against which individual behaviors, configurations, accounts, or processes are evaluated for conformance, so that a finding of "violation of organizational policy" signals a deviation from these enterprise-level rules rather than from any single technical standard or system setting.verified
Organizational Registration AuthoritynounMWEEntity within the PKI that authenticates the identity and the organizational affiliation of the users.verified
organizational risk tolerancenounMWEThe level of risk an organization is willing to take in order to achieve a potential desired result.verified
organizational systemnounMWEAn information system — comprising hardware, software, firmware, data, personnel, and associated facilities — that is owned, operated, or controlled by or on behalf of an organization and falls within that organization's authorization boundary and governance responsibility. It is the entity inside whose authorization boundary services and components reside, as distinct from external system services used by but not part of the system. In NIST's Risk Management Framework and related publications (SP 800-53 Rev. 5, SP 800-171 Rev. 3, SP 800-37 Rev. 2), the term serves as the consistent scope marker for applying security and privacy controls: organizations employ configuration settings, access controls, and other safeguards on the commercial IT products that compose their organizational systems. The controls in SP 800-53 are designed to protect organizational operations and assets through an organization-wide risk management process applied to these systems.verified
organizational tasknounMWEThis is a compositional phrase, not a term of art. "Organizational tasks" simply means the work activities, duties, and functions that a person (or automated process) is formally assigned to carry out on behalf of the organization — the ordinary sense of both words stacked together. In NIST SP 800-53 AC-6 (Least Privilege), the phrase appears as the boundary criterion for authorized access: systems should "allow only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks." NIST's own glossary defines a "task" simply as "an activity that is directed toward the achievement of organizational objectives," confirming that "organizational tasks" carries no meaning beyond that combination. Earlier NIST SP 800-53 revisions express the same idea slightly differently — "tasks in accordance with organizational missions and business functions" — showing that the expression is paraphrasable and interchangeable, which is characteristic of a compositional phrase rather than a fixed term of art.verified
Organizational UsernounMWEAn organizational employee or an individual the organization deems to have equivalent status of an employee (e.g., contractor, guest researcher, individual detailed from another organization, individual from allied nation).verified
Organophosphate Nerve AgentnounMWEany of a series of nerve agents containing organophosphate compounds first synthesized by German chemists in 1936verified
Oriental BittersweetnounMWEornamental Asiatic vine with showy orange-yellow fruit with a scarlet arilverified
Oriental Bush CherrynounMWEwoody oriental plant with smooth unfurrowed red fruit grown especially for its white or pale pink blossomsverified
Oriental CherrynounMWEornamental tree with inedible fruits widely cultivated in many varieties for its white blossomsverified
Oriental CockroachnounMWEdark brown cockroach originally from orient now nearly cosmopolitan in distributionverified
Oriental PoppynounMWEcommonly cultivated Asiatic perennial poppy having stiff heavily haired leaves and bright scarlet or pink to orange flowersverified
Oriental RoachnounMWEdark brown cockroach originally from orient now nearly cosmopolitan in distributionverified
Oriental SprucenounMWEevergreen tree of the Caucasus and Asia Minor used as an ornamental having pendulous branchletsverified
Originating depository financial institution (ODFI)nounMWEA participating financial institution that originates entries at the request of and by agreement with its originators in accordance with the provisions of the NACHA rules.verified
Origination FeenounMWEa fee charged to a borrower (especially for a mortgage loan) to cover the costs of initiating the loanverified
origination functionnounMWEAny of the processes required to initiate an automated clearing house transaction.verified
Orinasal PhonenounMWEa speech sound produced with both the oral and nasal passages open, as heard in French nasal vowelsverified
Orphan SitenounMWEa toxic waste area where the polluter could not be identified or the polluter refused to take action or pay for the cleanupverified
Orthoboric AcidnounMWEa white or colorless slightly acid solid that is soluble in water and ethanolverified
Orthodontic TreatmentnounMWEdental treatment that corrects irregularities of the teeth or of the relation of the teeth to surrounding anatomyverified
Orthodox SleepnounMWEa recurring sleep state during which rapid eye movements do not occur and dreaming does not occurverified
Orthomorphic ProjectionnounMWEa map projection in which a small area is rendered in its true shapeverified
Orthopterous InsectnounMWEany of various insects having leathery forewings and membranous hind wings and chewing mouthpartsverified
Orthostatic HypotensionnounMWElow blood pressure occurring in some people when they stand upverified
Os CapitatumnounMWEthe wrist bone with a rounded head shape that articulates with the 3rd metacarpusverified
Os FrontalenounMWEthe large cranial bone forming the front part of the cranium: includes the upper part of the orbitsverified
Os HyoideumnounMWEa U-shaped bone at the base of the tongue that supports the tongue musclesverified
Os LongumnounMWEin limbs of vertebrate animals: a long cylindrical bone that contains marrowverified
Os PalatinumnounMWEeither of two irregularly shaped bones that form the back of the hard palate and helps to form the nasal cavity and the floor of the orbitsverified
Os SesamoideumnounMWEany of several small round bones formed in a tendon where it passes over a jointverified
Os TemporalenounMWEa thick bone forming the side of the human cranium and encasing the inner earverified
Os TrapeziumnounMWEthe wrist bone on the thumb side of the hand that articulates with the 1st and 2nd metacarpalsverified
Os TriquetrumnounMWEa wrist bone that articulates with the pisiform and hamate and lunate bonesverified
Os ZygomaticumnounMWEthe arch of bone beneath the eye that forms the prominence of the cheekverified
Osage OrangenounMWEsmall shrubby deciduous yellowwood tree of south central United States having spines, glossy dark green leaves and an inedible fruit that resembles an orangeverified