home/glossary/system requirements

system requirements

nounid 163481·updated Aug 30, 2026
verified

Specifications regarding how the system should function to ( a ) meet the entity's commitments to customers and others (such as customers' customers); ( b ) meet the entity's commitments to suppliers and business partners; ( c ) comply with relevant laws and regulations and guidelines of industry groups, such as business or trade associations; and ( d ) achieve other entity objectives that are relevant to the trust services category or categories addressed by the description. Requirements are often specified in the entity's system policies and procedures, system design documentation, contracts with customers, and government regulations. System requirements may result from the entity's commitments relating to security, availability, processing integrity, confidentiality, or privacy. For example, a commitment to programmatically enforce segregation of duties between data entry and data approval creates system requirements regarding user access administration.

MWE

Source

document
2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (with Revised Points of Focus - 2022)
found in
glossary section
discovery
AuthoritativeImport

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.01.h ¶ 2

Classifications

Entity Type

Requirement95%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated85%llm-generatedllm:claude-haiku-4-5

Information Class

unclassified

Variants

No variants recorded
This term has no surface-form variants in the lexicon yet, so it tags only its canonical form.

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
TSP Section 1001 senseview framework →
§1 · glossary
Specifications regarding how the system should function to ( a ) meet the entity's commitments to customers and others (such as customers' customers); ( b ) meet the entity's commitments to suppliers and business partners; ( c ) comply with relevant laws and regulations and guidelines of industry groups, such as business or trade associations; and ( d ) achieve other entity objectives that are relevant to the trust services category or categories addressed by the description. Requirements are often specified in the entity's system policies and procedures, system design documentation, contracts with customers, and government regulations. System requirements may result from the entity's commitments relating to security, availability, processing integrity, confidentiality, or privacy. For example, a commitment to programmatically enforce segregation of duties between data entry and data approval creates system requirements regarding user access administration.
Attribution from the CKI glossary mapping stage (glossary)
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
Specifications regarding how the system should function to ( a ) meet the entity's commitments to customers and others (such as customers' customers); ( b ) meet the entity's commitments to suppliers and business partners; ( c ) comply with relevant laws and regulations and guidelines of industry groups, such as business or trade associations; and ( d ) achieve other entity objectives that are relevant to the trust services category or categories addressed by the description. Requirements are often specified in the entity's system policies and procedures, system design documentation, contracts with customers, and government regulations. System requirements may result from the entity's commitments relating to security, availability, processing integrity, confidentiality, or privacy. For example, a commitment to programmatically enforce segregation of duties between data entry and data approval creates system requirements regarding user access administration.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.