organization-defined security-relevant information
163570·updated Sep 1, 2026A parameterized placeholder used in NIST SP 800-53 access-control statements, combining the standard `[Assignment: organization-defined …]` tailoring syntax with the defined term "security-relevant information" — information within a system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data. The full expression does not coin a new concept; it instructs each organization to enumerate, from that category, the specific assets it will protect — such as filtering rules for routers/firewalls, cryptographic key management information, configuration parameters for security services, and access control lists. In practice it appears in control AC-3(5), where the information system prevents access to `[Assignment: organization-defined security-relevant information]` except during secure, non-operable system states, leaving the exact scope of that information for each organization to specify in its System Security Plan.
Source
] and [ Assignment: organization-definedthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
** A parameterized scope of protection within the NIST SP 800-53 access-control framework — specifically, any information within information systems that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce system security policies or maintain the isolation of code and data — whose exact membership is left for each organization to specify for its own environment. Canonical examples include access control lists, filtering rules for routers or firewalls, configuration parameters for security services, and cryptographic key management information. In practice the phrase serves as an `[Assignment:]` placeholder in control text — specifically preventing access to that designated set of information except during secure, non-operable system states — requiring the implementing organization to enumerate the specific data items that qualify before the control can be considered satisfied. **VERDICT:** TERM_OF_ART **Sources:** - NIST CSRC Glossary, *security-relevant information*: https://csrc.nist.gov/glossary/term/security_relevant_information (NIST SP 800-53 Rev. 5) - CSF.Tools, *AC-3(5): Secur
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- organization-defined security-relevant informations
- possessive
- organization-defined security-relevant information's
- pluralpossessive
- organization-defined security-relevant informations'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A parameterized placeholder used in NIST SP 800-53 access-control statements, combining the standard `[Assignment: organization-defined …]` tailoring syntax with the defined term "security-relevant information" — information within a system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data. The full expression does not coin a new concept; it instructs each organization to enumerate, from that category, the specific assets it will protect — such as filtering rules for routers/firewalls, cryptographic key management information, configuration parameters for security services, and access control lists. In practice it appears in control AC-3(5), where the information system prevents access to `[Assignment: organization-defined security-relevant information]` except during secure, non-operable system states, leaving the exact scope of that information for each organization to specify in its System Security Plan.DR-088 backfill from the noun definition column