home/glossary/defined period

defined period

nounid 163520·updated Aug 30, 2026
verified

A policy-established, organization-configurable duration of elapsed time—measured in minutes, hours, or days—that serves as a threshold triggering an automated security enforcement action when that duration expires without the expected activity. Across NIST SP 800-53/800-171, CIS Controls, PCI DSS, ISO/IEC 27001, and HIPAA, it functions as the configurable variable inside controls such as session locking, session termination, account disablement, and token expiry: the control specifies *that* enforcement must occur automatically, while the defined period is the organization-set value governing *when* it fires. It is intentionally left as a parameter rather than a fixed value in most frameworks because the appropriate threshold varies by asset type, data sensitivity, and risk posture—though regulators sometimes cap it (e.g., PCI DSS at 15 minutes for idle sessions, CIS Controls at 15 minutes for general-purpose OSes and 2 minutes for mobile devices).

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0165
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
when they are expecting inactivity longer than the defined period. Automatic enforcement ofthe sentence this term was read in
A web lookup ran when this term was proposed

A policy-specified duration of time that an organization sets as a threshold to trigger an automated or required manual security action — such as session termination, account disablement, identifier invalidation, or connection tear-down — when that threshold is crossed without qualifying activity. It functions as an organization-defined control parameter: the variable part of a security control that an organization instantiates during tailoring by assigning a concrete value appropriate to its risk posture. Authority documents use the phrase as a placeholder rather than a fixed value, deliberately leaving the numeric duration open; for example, NIST SP 800-171 requires organizations to "prevent reuse of identifiers for a defined period" and to "disable identifiers after a defined period of inactivity," while DoD guidance explicitly notes there are no minimum acceptable values for "a defined period" — the values are left to the contractor to determine. Across contexts the expression recurs wherever a control must fire after elapsed time — inactivity logout, network-session termination "after a defined period of inactivity," cryptographic key rotation windows, and similar — always mea

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems2 citations · 2 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.01.h ¶ 403.01.11 ¶ 2

Classifications

Entity Type

Requirement88%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated90%rule-basedr:sens.regulated.framework.v1

Information Class

unclassified

Variants

plural
defined periods
possessive
defined period's
pluralpossessive
defined periods'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A policy-established, organization-configurable duration of elapsed time—measured in minutes, hours, or days—that serves as a threshold triggering an automated security enforcement action when that duration expires without the expected activity. Across NIST SP 800-53/800-171, CIS Controls, PCI DSS, ISO/IEC 27001, and HIPAA, it functions as the configurable variable inside controls such as session locking, session termination, account disablement, and token expiry: the control specifies *that* enforcement must occur automatically, while the defined period is the organization-set value governing *when* it fires. It is intentionally left as a parameter rather than a fixed value in most frameworks because the appropriate threshold varies by asset type, data sensitivity, and risk posture—though regulators sometimes cap it (e.g., PCI DSS at 15 minutes for idle sessions, CIS Controls at 15 minutes for general-purpose OSes and 2 minutes for mobile devices).
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.