organization-defined frequency
163571·updated Sep 1, 2026An *organization-defined frequency* is an instance of an **organization-defined control parameter** — the variable part of a security or privacy control that an organization fills in during the tailoring process by assigning a concrete value. As a frequency parameter specifically, it is a placeholder in a control statement that requires the implementing organization to decide *how often* a required activity — such as a review, update, assessment, or report — must recur, calibrating the cadence to the organization's own risk environment, mission, and operational tempo rather than prescribing a universal interval. The rationale is that circumstances such as organizational missions, business functions, environments of operation, technologies, or threat change over time, making periodic repetition of certain activities necessary and the appropriate interval something each organization must judge for itself. In practice, it appears throughout NIST control catalogs as an *Assignment* notation — e.g., `[Assignment: organization-defined frequency]` — wherever a control mandates a recurring action and leaves the interval open for the organization to specify, with implementers then documenti
Source
Review the privileges assigned to roles or classes of users [ Assignment: organization-defined frequency ] to validate the need for such privileges.the sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- organization defined control parameter
- CHAPTER THREE PAGE 1 ACCESS CONTROL Quick link to Access Control summary table
- Organization-Defined Parameters for National Institute of ...
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A control-tailoring placeholder — specifically an *organization-defined parameter* (ODP) of the temporal type — embedded in the statement of a security or privacy control to indicate that the implementing organization must supply a concrete time interval (e.g., quarterly, annually) before the control can be operationalized. It represents the variable part of a control or control enhancement that can be instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a pre-defined list provided as part of the control or control enhancement. Across the NIST SP 800-53 and SP 800-171 families it appears wherever a standard mandates a periodic action — review, update, assessment, reporting — but intentionally leaves the cadence unspecified so that each organization can calibrate it to its own risk posture; a key aspect of these publications is the inclusion of organization-defined parameters (ODPs), which allow organizations to tailor select security controls to specific security requirements, as determined by unique organizational risk management strategies. A superior authority (e.g., a regulatory overlay such as
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- organization-defined frequencies
- possessive
- organization-defined frequency's
- pluralpossessive
- organization-defined frequencies'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 24 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- An *organization-defined frequency* is an instance of an **organization-defined control parameter** — the variable part of a security or privacy control that an organization fills in during the tailoring process by assigning a concrete value. As a frequency parameter specifically, it is a placeholder in a control statement that requires the implementing organization to decide *how often* a required activity — such as a review, update, assessment, or report — must recur, calibrating the cadence to the organization's own risk environment, mission, and operational tempo rather than prescribing a universal interval. The rationale is that circumstances such as organizational missions, business functions, environments of operation, technologies, or threat change over time, making periodic repetition of certain activities necessary and the appropriate interval something each organization must judge for itself. In practice, it appears throughout NIST control catalogs as an *Assignment* notation — e.g., `[Assignment: organization-defined frequency]` — wherever a control mandates a recurring action and leaves the interval open for the organization to specify, with implementers then documentiDR-088 backfill from the noun definition column