defined period
163520·updated Aug 30, 2026A policy-established, organization-configurable duration of elapsed time—measured in minutes, hours, or days—that serves as a threshold triggering an automated security enforcement action when that duration expires without the expected activity. Across NIST SP 800-53/800-171, CIS Controls, PCI DSS, ISO/IEC 27001, and HIPAA, it functions as the configurable variable inside controls such as session locking, session termination, account disablement, and token expiry: the control specifies *that* enforcement must occur automatically, while the defined period is the organization-set value governing *when* it fires. It is intentionally left as a parameter rather than a fixed value in most frameworks because the appropriate threshold varies by asset type, data sensitivity, and risk posture—though regulators sometimes cap it (e.g., PCI DSS at 15 minutes for idle sessions, CIS Controls at 15 minutes for general-purpose OSes and 2 minutes for mobile devices).
Source
when they are expecting inactivity longer than the defined period. Automatic enforcement ofthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- 4.3: Configure Automatic Session Locking on Enterprise Assets - CSF Tools
- Disable identifiers after a defined period of inactivity - NIST SP 800 171 Compliance Experts - On Call Compliance Solutions
- AC.L2-3.1.11 Session Termination - DIB SCC CyberAssist
- 🔐 Fintech App Security: 🕒 Best Practices for Inactivity Timeouts ⏳ (ISO, PCI-DSS & NIST Guidelines) 🚀 - Cyberbuddies Academy Blog
- PCI DSS Session Timeout Enforcement: Why It Matters and How to Implement It
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A policy-specified duration of time that an organization sets as a threshold to trigger an automated or required manual security action — such as session termination, account disablement, identifier invalidation, or connection tear-down — when that threshold is crossed without qualifying activity. It functions as an organization-defined control parameter: the variable part of a security control that an organization instantiates during tailoring by assigning a concrete value appropriate to its risk posture. Authority documents use the phrase as a placeholder rather than a fixed value, deliberately leaving the numeric duration open; for example, NIST SP 800-171 requires organizations to "prevent reuse of identifiers for a defined period" and to "disable identifiers after a defined period of inactivity," while DoD guidance explicitly notes there are no minimum acceptable values for "a defined period" — the values are left to the contractor to determine. Across contexts the expression recurs wherever a control must fire after elapsed time — inactivity logout, network-session termination "after a defined period of inactivity," cryptographic key rotation windows, and similar — always mea
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- defined periods
- possessive
- defined period's
- pluralpossessive
- defined periods'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A policy-established, organization-configurable duration of elapsed time—measured in minutes, hours, or days—that serves as a threshold triggering an automated security enforcement action when that duration expires without the expected activity. Across NIST SP 800-53/800-171, CIS Controls, PCI DSS, ISO/IEC 27001, and HIPAA, it functions as the configurable variable inside controls such as session locking, session termination, account disablement, and token expiry: the control specifies *that* enforcement must occur automatically, while the defined period is the organization-set value governing *when* it fires. It is intentionally left as a parameter rather than a fixed value in most frameworks because the appropriate threshold varies by asset type, data sensitivity, and risk posture—though regulators sometimes cap it (e.g., PCI DSS at 15 minutes for idle sessions, CIS Controls at 15 minutes for general-purpose OSes and 2 minutes for mobile devices).DR-088 backfill from the noun definition column