home/glossary/organization-defined personnel

organization-defined personnel

nounid 163578·updated Sep 1, 2026
verified

An organization-defined parameter (ODP) — specifically one whose value is a set of human recipients identified by job title, functional role, or organizational position — that an implementing organization must supply during the control-tailoring process to make a security or privacy control requirement complete and enforceable. It is the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list. Across NIST SP 800-53 and related frameworks, the assignment operation allows an organization to assign a specific, organization-defined value to the control — for example, assigning a list of roles to be notified. In practice the expression appears throughout policy-dissemination, notification, approval, and training controls — such as developing, documenting, and disseminating personnel security policy to [Assignment: organization-defined personnel or roles] or requiring third-party providers to notify [Assignment: organization-defined personnel or roles] of any personnel transfers or terminations — where each implementing organization

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0203
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
on the system to [ Assignment: organization-defined personnel or roles ].the sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

** An organization-defined control parameter — specifically a placeholder within a NIST SP 800-53 (and related framework) security or privacy control — that the implementing organization must resolve during the tailoring process by naming the specific individuals, positions, or role titles who will be recipients of, approvers for, or notifiers in a given control action. It is "the variable part of a control or control enhancement that can be instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a pre-defined list." Across the catalog, it appears wherever a control must be directed at *someone* — for example, disseminating a security policy, receiving third-party termination notifications, restricting privileged accounts, or reporting atypical usage — and the standard deliberately leaves the slot open so each organization can fill it with whichever job titles, named roles, or individual positions fit its own structure. DISA's Control Correlation Identifier (CCI) decomposition makes the intent explicit: it defines the obligation as "defines the personnel or roles to be recipients" of a given policy or

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.06.a

Classifications

Entity Type

Group100%manual reviewaxis_review_queue.v1

Sensitivity

Regulated90%llm-generatedllm:claude-haiku-4-5

Information Class

unclassified

Variants

plural
organization-defined personnels
possessive
organization-defined personnel's
pluralpossessive
organization-defined personnels'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
An organization-defined parameter (ODP) — specifically one whose value is a set of human recipients identified by job title, functional role, or organizational position — that an implementing organization must supply during the control-tailoring process to make a security or privacy control requirement complete and enforceable. It is the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list. Across NIST SP 800-53 and related frameworks, the assignment operation allows an organization to assign a specific, organization-defined value to the control — for example, assigning a list of roles to be notified. In practice the expression appears throughout policy-dissemination, notification, approval, and training controls — such as developing, documenting, and disseminating personnel security policy to [Assignment: organization-defined personnel or roles] or requiring third-party providers to notify [Assignment: organization-defined personnel or roles] of any personnel transfers or terminations — where each implementing organization
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.