organization-defined personnel
163578·updated Sep 1, 2026An organization-defined parameter (ODP) — specifically one whose value is a set of human recipients identified by job title, functional role, or organizational position — that an implementing organization must supply during the control-tailoring process to make a security or privacy control requirement complete and enforceable. It is the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list. Across NIST SP 800-53 and related frameworks, the assignment operation allows an organization to assign a specific, organization-defined value to the control — for example, assigning a list of roles to be notified. In practice the expression appears throughout policy-dissemination, notification, approval, and training controls — such as developing, documenting, and disseminating personnel security policy to [Assignment: organization-defined personnel or roles] or requiring third-party providers to notify [Assignment: organization-defined personnel or roles] of any personnel transfers or terminations — where each implementing organization
Source
on the system to [ Assignment: organization-defined personnel or roles ].the sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
- organization-defined parameter - Glossary | CSRC
- assignment operation - Glossary | CSRC
- PS-1: Personnel Security Policy And Procedures - CSF Tools
- PS-7: Third-Party Personnel Security - CSF Tools
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
** An organization-defined control parameter — specifically a placeholder within a NIST SP 800-53 (and related framework) security or privacy control — that the implementing organization must resolve during the tailoring process by naming the specific individuals, positions, or role titles who will be recipients of, approvers for, or notifiers in a given control action. It is "the variable part of a control or control enhancement that can be instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a pre-defined list." Across the catalog, it appears wherever a control must be directed at *someone* — for example, disseminating a security policy, receiving third-party termination notifications, restricting privileged accounts, or reporting atypical usage — and the standard deliberately leaves the slot open so each organization can fill it with whichever job titles, named roles, or individual positions fit its own structure. DISA's Control Correlation Identifier (CCI) decomposition makes the intent explicit: it defines the obligation as "defines the personnel or roles to be recipients" of a given policy or
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- organization-defined personnels
- possessive
- organization-defined personnel's
- pluralpossessive
- organization-defined personnels'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- An organization-defined parameter (ODP) — specifically one whose value is a set of human recipients identified by job title, functional role, or organizational position — that an implementing organization must supply during the control-tailoring process to make a security or privacy control requirement complete and enforceable. It is the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list. Across NIST SP 800-53 and related frameworks, the assignment operation allows an organization to assign a specific, organization-defined value to the control — for example, assigning a list of roles to be notified. In practice the expression appears throughout policy-dissemination, notification, approval, and training controls — such as developing, documenting, and disseminating personnel security policy to [Assignment: organization-defined personnel or roles] or requiring third-party providers to notify [Assignment: organization-defined personnel or roles] of any personnel transfers or terminations — where each implementing organizationDR-088 backfill from the noun definition column