home/glossary/organization-defined time period

organization-defined time period

nounid 163500·updated Aug 30, 2026
verified

A placeholder variable embedded within a security or privacy control statement—a species of **organization-defined parameter (ODP)**—that reserves a duration value for the implementing organization to specify during the tailoring process. It is "the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list provided as part of the control or control enhancement." In practice, the standards body intentionally leaves the duration blank because the correct threshold differs by context, risk tolerance, and applicable regulatory constraints; organization-defined parameters are used in NIST SP 800-53 controls "to provide flexibility to federal agencies in tailoring controls to support specific organizational missions or business functions and to manage risk." Once filled in, the chosen value becomes part of the enforceable requirement and is subject to assessment: once ODPs have been defined, they become part of the security requirement and can be assessed as such, and they help simplify assessments by providing greater specificity and

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0152
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
The accounts have been inactive for [ Assignment: organization-defined time period ],the sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A placeholder variable embedded within a security or privacy control statement—a species of **organization-defined parameter (ODP)**—that reserves a duration value for the implementing organization to specify during the tailoring process. It is "the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list provided as part of the control or control enhancement." In practice, the standards body intentionally leaves the duration blank because the correct threshold differs by context, risk tolerance, and applicable regulatory constraints; organization-defined parameters are used in NIST SP 800-53 controls "to provide flexibility to federal agencies in tailoring controls to support specific organizational missions or business functions and to manage risk." Once filled in, the chosen value becomes part of the enforceable requirement and is subject to assessment: once ODPs have been defined, they become part of the security requirement and can be assessed as such, and they help simplify assessments by providing greater specificity and

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems16 citations · 16 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.01.f.203.01.01.g.103.01.01.g.203.01.01.g.303.01.01.h03.01.08.a03.01.08.b03.01.10.a03.03.04.a03.05.05.c03.06.02.b03.06.04.a.103.09.02.a.103.13.09 ¶ 103.14.01.b03.14.01.b ¶ 1

Classifications

Entity Type

Requirement92%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated88%llm-generatedllm:claude-haiku-4-5

Information Class

Cui65%llm-generatedllm:claude-haiku-4-5

Variants

plural
organization-defined time periods
possessive
organization-defined time period's
pluralpossessive
organization-defined time periods'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 16 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A placeholder variable embedded within a security or privacy control statement—a species of **organization-defined parameter (ODP)**—that reserves a duration value for the implementing organization to specify during the tailoring process. It is "the variable part of a control or control enhancement that is instantiated by an organization during the tailoring process by either assigning an organization-defined value or selecting a value from a predefined list provided as part of the control or control enhancement." In practice, the standards body intentionally leaves the duration blank because the correct threshold differs by context, risk tolerance, and applicable regulatory constraints; organization-defined parameters are used in NIST SP 800-53 controls "to provide flexibility to federal agencies in tailoring controls to support specific organizational missions or business functions and to manage risk." Once filled in, the chosen value becomes part of the enforceable requirement and is subject to assessment: once ODPs have been defined, they become part of the security requirement and can be assessed as such, and they help simplify assessments by providing greater specificity and
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.