home/glossary/organization-defined security function

organization-defined security function

nounid 163569·updated Sep 1, 2026
verified

** A placeholder construct used in control frameworks — most prominently NIST SP 800-53 and NIST SP 800-171 — where a security control statement is intentionally left partially open, requiring each implementing organization to enumerate the specific security-enforcing capabilities (hardware, software, or firmware mechanisms such as account management, access authorization configuration, audit-event settings, and intrusion-detection parameter management) that are subject to the control's requirement. It functions as an *assignment operation*: a control parameter that allows an organization to assign a specific, organization-defined value to the control or control enhancement. In practice, many NIST controls are not "complete" as published but require "fill in the blanks," and these blanks are called Organization-defined Values or Organization-defined Parameters; "organization-defined security functions" is one such parameter, naming whichever protective capabilities the organization determines fall under least-privilege or access-authorization scope — for example, establishing system accounts and assigning privileges, installing software, configuring access authorizations, configuri

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0194
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
Authorize access to [ Assignment: organization-definedthe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A parameter-bearing descriptor used in control statements to denote the subset of a system's policy-enforcing hardware, software, and firmware capabilities — formally called "security functions" — that a particular organization has selected, named, or scoped for a given control requirement. It is distinguished from the base term "security functions" by the "organization-defined" qualifier, which is a standard NIST SP 800-53 templating convention signaling that the implementing organization must enumerate the specific functions in its own security plan rather than accepting a universal list. In practice, such functions include account management interfaces, access-authorization configurations, audit-event settings, and intrusion-detection parameters, but the exact set is determined by each organization's system boundaries and risk decisions. The phrase is compositional: its meaning is fully derived from its two established components and it carries no additional sense beyond them.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.05.b

Classifications

Entity Type

Requirement85%manual reviewllm:claude-haiku-4-5

Sensitivity

Regulated90%llm-generatedllm:claude-haiku-4-5

Information Class

70%llm-generatedmulti_axis_classifier_queued.v1

Variants

plural
organization-defined security functions
possessive
organization-defined security function's
pluralpossessive
organization-defined security functions'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
** A placeholder construct used in control frameworks — most prominently NIST SP 800-53 and NIST SP 800-171 — where a security control statement is intentionally left partially open, requiring each implementing organization to enumerate the specific security-enforcing capabilities (hardware, software, or firmware mechanisms such as account management, access authorization configuration, audit-event settings, and intrusion-detection parameter management) that are subject to the control's requirement. It functions as an *assignment operation*: a control parameter that allows an organization to assign a specific, organization-defined value to the control or control enhancement. In practice, many NIST controls are not "complete" as published but require "fill in the blanks," and these blanks are called Organization-defined Values or Organization-defined Parameters; "organization-defined security functions" is one such parameter, naming whichever protective capabilities the organization determines fall under least-privilege or access-authorization scope — for example, establishing system accounts and assigning privileges, installing software, configuring access authorizations, configuri
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.