home/glossary/organization-defined types of cryptography

organization-defined types of cryptography

nounid 163607·updated Sep 14, 2026
candidate

An organization-defined parameter (ODP) placeholder used in risk-based security control frameworks — specifically in NIST SP 800-53 control SC-13 (Cryptographic Protection) and its derivatives such as SP 800-171 — that an organization is required to populate with the specific cryptographic mechanisms, standards, or algorithms it has selected for each designated cryptographic use case. ODPs of this kind are included in certain security requirements to provide flexibility through assignment and selection operations, allowing organizations to specify values tailored to their specific protection needs. In practice, it pairs with a companion ODP for "organization-defined cryptographic uses," so that for each use case an organization names, it must also designate the corresponding type of cryptography to implement. Acceptable values are drawn from applicable standards: generally applicable cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography; for example, organizations protecting classified information may specify the use of NSA-approved cryptography.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0122
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
organizationthe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

An organization-defined parameter (ODP) placeholder used in risk-based security control frameworks — specifically in NIST SP 800-53 control SC-13 (Cryptographic Protection) and its derivatives such as SP 800-171 — that an organization is required to populate with the specific cryptographic mechanisms, standards, or algorithms it has selected for each designated cryptographic use case. ODPs of this kind are included in certain security requirements to provide flexibility through assignment and selection operations, allowing organizations to specify values tailored to their specific protection needs. In practice, it pairs with a companion ODP for "organization-defined cryptographic uses," so that for each use case an organization names, it must also designate the corresponding type of cryptography to implement. Acceptable values are drawn from applicable standards: generally applicable cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography; for example, organizations protecting classified information may specify the use of NSA-approved cryptography.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

No recorded attestations. They are written when an MWE tagging stage is completed, stamped with the pack version and the document’s digest.

Classifications

Entity Type

Unknownauthoritativecki_proposal_default_pending_classifier

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
organization-defined types of cryptographies
possessive
organization-defined types of cryptography's
pluralpossessive
organization-defined types of cryptographies'

Framework definitions

Web lookup drafts1 senseview framework →
§1 · web_lookup_draft
An organization-defined parameter (ODP) placeholder used in risk-based security control frameworks — specifically in NIST SP 800-53 control SC-13 (Cryptographic Protection) and its derivatives such as SP 800-171 — that an organization is required to populate with the specific cryptographic mechanisms, standards, or algorithms it has selected for each designated cryptographic use case. ODPs of this kind are included in certain security requirements to provide flexibility through assignment and selection operations, allowing organizations to specify values tailored to their specific protection needs. In practice, it pairs with a companion ODP for "organization-defined cryptographic uses," so that for each use case an organization names, it must also designate the corresponding type of cryptography to implement. Acceptable values are drawn from applicable standards: generally applicable cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography; for example, organizations protecting classified information may specify the use of NSA-approved cryptography.
Drafted by the propose-term web lookup (PD-018); a curator confirms or replaces it.

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.