organization-defined time period
163500·updated Aug 30, 2026A placeholder variable embedded within a security or privacy control statement—a species of **organization-defined parameter (ODP)**—that reserves a duration value for the implementing organization to specify during the tailoring process. It is "the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list provided as part of the control or control enhancement." In practice, the standards body intentionally leaves the duration blank because the correct threshold differs by context, risk tolerance, and applicable regulatory constraints; organization-defined parameters are used in NIST SP 800-53 controls "to provide flexibility to federal agencies in tailoring controls to support specific organizational missions or business functions and to manage risk." Once filled in, the chosen value becomes part of the enforceable requirement and is subject to assessment: once ODPs have been defined, they become part of the security requirement and can be assessed as such, and they help simplify assessments by providing greater specificity and
Source
The accounts have been inactive for [ Assignment: organization-defined time period ],the sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- organization-defined parameter - Glossary | CSRC
- FREQUENTLY ASKED QUESTIONS NIST SP 800-171r3 and NIST SP 800-171Ar3
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A placeholder variable embedded within a security or privacy control statement—a species of **organization-defined parameter (ODP)**—that reserves a duration value for the implementing organization to specify during the tailoring process. It is "the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list provided as part of the control or control enhancement." In practice, the standards body intentionally leaves the duration blank because the correct threshold differs by context, risk tolerance, and applicable regulatory constraints; organization-defined parameters are used in NIST SP 800-53 controls "to provide flexibility to federal agencies in tailoring controls to support specific organizational missions or business functions and to manage risk." Once filled in, the chosen value becomes part of the enforceable requirement and is subject to assessment: once ODPs have been defined, they become part of the security requirement and can be assessed as such, and they help simplify assessments by providing greater specificity and
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- organization-defined time periods
- possessive
- organization-defined time period's
- pluralpossessive
- organization-defined time periods'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 16 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A placeholder variable embedded within a security or privacy control statement—a species of **organization-defined parameter (ODP)**—that reserves a duration value for the implementing organization to specify during the tailoring process. It is "the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list provided as part of the control or control enhancement." In practice, the standards body intentionally leaves the duration blank because the correct threshold differs by context, risk tolerance, and applicable regulatory constraints; organization-defined parameters are used in NIST SP 800-53 controls "to provide flexibility to federal agencies in tailoring controls to support specific organizational missions or business functions and to manage risk." Once filled in, the chosen value becomes part of the enforceable requirement and is subject to assessment: once ODPs have been defined, they become part of the security requirement and can be assessed as such, and they help simplify assessments by providing greater specificity andDR-088 backfill from the noun definition column