defined period
163520·updated Aug 30, 2026No definition recorded.
Composition
Source
when they are expecting inactivity longer than the defined period. Automatic enforcement ofthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- 4.3: Configure Automatic Session Locking on Enterprise Assets - CSF Tools
- Disable identifiers after a defined period of inactivity - NIST SP 800 171 Compliance Experts - On Call Compliance Solutions
- AC.L2-3.1.11 Session Termination - DIB SCC CyberAssist
- 🔐 Fintech App Security: 🕒 Best Practices for Inactivity Timeouts ⏳ (ISO, PCI-DSS & NIST Guidelines) 🚀 - Cyberbuddies Academy Blog
- PCI DSS Session Timeout Enforcement: Why It Matters and How to Implement It
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A policy-specified duration of time that an organization sets as a threshold to trigger an automated or required manual security action — such as session termination, account disablement, identifier invalidation, or connection tear-down — when that threshold is crossed without qualifying activity. It functions as an organization-defined control parameter: the variable part of a security control that an organization instantiates during tailoring by assigning a concrete value appropriate to its risk posture. Authority documents use the phrase as a placeholder rather than a fixed value, deliberately leaving the numeric duration open; for example, NIST SP 800-171 requires organizations to "prevent reuse of identifiers for a defined period" and to "disable identifiers after a defined period of inactivity," while DoD guidance explicitly notes there are no minimum acceptable values for "a defined period" — the values are left to the contractor to determine. Across contexts the expression recurs wherever a control must fire after elapsed time — inactivity logout, network-session termination "after a defined period of inactivity," cryptographic key rotation windows, and similar — always mea
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
No recorded attestations. They are written when an MWE tagging stage is completed, stamped with the pack version and the document’s digest.