organization-defined security-relevant information
163570·updated Sep 1, 2026No definition recorded.
Composition
Source
] and [ Assignment: organization-definedthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
** A parameterized scope of protection within the NIST SP 800-53 access-control framework — specifically, any information within information systems that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce system security policies or maintain the isolation of code and data — whose exact membership is left for each organization to specify for its own environment. Canonical examples include access control lists, filtering rules for routers or firewalls, configuration parameters for security services, and cryptographic key management information. In practice the phrase serves as an `[Assignment:]` placeholder in control text — specifically preventing access to that designated set of information except during secure, non-operable system states — requiring the implementing organization to enumerate the specific data items that qualify before the control can be considered satisfied. **VERDICT:** TERM_OF_ART **Sources:** - NIST CSRC Glossary, *security-relevant information*: https://csrc.nist.gov/glossary/term/security_relevant_information (NIST SP 800-53 Rev. 5) - CSF.Tools, *AC-3(5): Secur
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
No recorded attestations. They are written when an MWE tagging stage is completed, stamped with the pack version and the document’s digest.