home/glossary/organization-defined frequency

organization-defined frequency

nounid 163571·updated Sep 1, 2026
verified

An *organization-defined frequency* is an instance of an **organization-defined control parameter** — the variable part of a security or privacy control that an organization fills in during the tailoring process by assigning a concrete value. As a frequency parameter specifically, it is a placeholder in a control statement that requires the implementing organization to decide *how often* a required activity — such as a review, update, assessment, or report — must recur, calibrating the cadence to the organization's own risk environment, mission, and operational tempo rather than prescribing a universal interval. The rationale is that circumstances such as organizational missions, business functions, environments of operation, technologies, or threat change over time, making periodic repetition of certain activities necessary and the appropriate interval something each organization must judge for itself. In practice, it appears throughout NIST control catalogs as an *Assignment* notation — e.g., `[Assignment: organization-defined frequency]` — wherever a control mandates a recurring action and leaves the interval open for the organization to specify, with implementers then documenti

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0195
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
Review the privileges assigned to roles or classes of users [ Assignment: organization-defined frequency ] to validate the need for such privileges.the sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A control-tailoring placeholder — specifically an *organization-defined parameter* (ODP) of the temporal type — embedded in the statement of a security or privacy control to indicate that the implementing organization must supply a concrete time interval (e.g., quarterly, annually) before the control can be operationalized. It represents the variable part of a control or control enhancement that can be instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a pre-defined list provided as part of the control or control enhancement. Across the NIST SP 800-53 and SP 800-171 families it appears wherever a standard mandates a periodic action — review, update, assessment, reporting — but intentionally leaves the cadence unspecified so that each organization can calibrate it to its own risk posture; a key aspect of these publications is the inclusion of organization-defined parameters (ODPs), which allow organizations to tailor select security controls to specific security requirements, as determined by unique organizational risk management strategies. A superior authority (e.g., a regulatory overlay such as

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems24 citations · 24 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.05.c03.02.01.b03.02.02.a.103.02.02.b03.03.01.b03.03.05.a03.04.01.b03.04.06.c03.04.08.c03.05.07.a03.05.12.e03.06.04.a.303.06.04.b03.10.01.c03.10.02.b03.11.01.b03.11.02.c03.12.01 ¶ 103.12.05.c03.14.02.c.103.15.01.b03.15.02.b03.15.03.d03.17.01.b

Classifications

Entity Type

Requirement85%manual reviewllm:claude-haiku-4-5

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
organization-defined frequencies
possessive
organization-defined frequency's
pluralpossessive
organization-defined frequencies'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 24 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
An *organization-defined frequency* is an instance of an **organization-defined control parameter** — the variable part of a security or privacy control that an organization fills in during the tailoring process by assigning a concrete value. As a frequency parameter specifically, it is a placeholder in a control statement that requires the implementing organization to decide *how often* a required activity — such as a review, update, assessment, or report — must recur, calibrating the cadence to the organization's own risk environment, mission, and operational tempo rather than prescribing a universal interval. The rationale is that circumstances such as organizational missions, business functions, environments of operation, technologies, or threat change over time, making periodic repetition of certain activities necessary and the appropriate interval something each organization must judge for itself. In practice, it appears throughout NIST control catalogs as an *Assignment* notation — e.g., `[Assignment: organization-defined frequency]` — wherever a control mandates a recurring action and leaves the interval open for the organization to specify, with implementers then documenti
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.