home/glossary/organization-defined security-relevant information

organization-defined security-relevant information

nounid 163570·updated Sep 1, 2026
verified

A parameterized placeholder used in NIST SP 800-53 access-control statements, combining the standard `[Assignment: organization-defined …]` tailoring syntax with the defined term "security-relevant information" — information within a system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data. The full expression does not coin a new concept; it instructs each organization to enumerate, from that category, the specific assets it will protect — such as filtering rules for routers/firewalls, cryptographic key management information, configuration parameters for security services, and access control lists. In practice it appears in control AC-3(5), where the information system prevents access to `[Assignment: organization-defined security-relevant information]` except during secure, non-operable system states, leaving the exact scope of that information for each organization to specify in its System Security Plan.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0194
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
] and [ Assignment: organization-definedthe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

** A parameterized scope of protection within the NIST SP 800-53 access-control framework — specifically, any information within information systems that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce system security policies or maintain the isolation of code and data — whose exact membership is left for each organization to specify for its own environment. Canonical examples include access control lists, filtering rules for routers or firewalls, configuration parameters for security services, and cryptographic key management information. In practice the phrase serves as an `[Assignment:]` placeholder in control text — specifically preventing access to that designated set of information except during secure, non-operable system states — requiring the implementing organization to enumerate the specific data items that qualify before the control can be considered satisfied. **VERDICT:** TERM_OF_ART **Sources:** - NIST CSRC Glossary, *security-relevant information*: https://csrc.nist.gov/glossary/term/security_relevant_information (NIST SP 800-53 Rev. 5) - CSF.Tools, *AC-3(5): Secur

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.05.b

Classifications

Entity Type

Requirement85%manual reviewllm:claude-haiku-4-5

Sensitivity

Regulated90%llm-generatedllm:claude-haiku-4-5

Information Class

70%llm-generatedmulti_axis_classifier_queued.v1

Variants

plural
organization-defined security-relevant informations
possessive
organization-defined security-relevant information's
pluralpossessive
organization-defined security-relevant informations'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A parameterized placeholder used in NIST SP 800-53 access-control statements, combining the standard `[Assignment: organization-defined …]` tailoring syntax with the defined term "security-relevant information" — information within a system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data. The full expression does not coin a new concept; it instructs each organization to enumerate, from that category, the specific assets it will protect — such as filtering rules for routers/firewalls, cryptographic key management information, configuration parameters for security services, and access control lists. In practice it appears in control AC-3(5), where the information system prevents access to `[Assignment: organization-defined security-relevant information]` except during secure, non-operable system states, leaving the exact scope of that information for each organization to specify in its System Security Plan.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.