organization-defined frequency
An *organization-defined frequency* is an instance of an **organization-defined control parameter** — the variable part of a security or privacy control that an organization fills in during the tailoring process by assigning a concrete value. As a frequency parameter specifically, it is a placeholder in a control statement that requires the implementing organization to decide *how often* a required activity — such as a review, update, assessment, or report — must recur, calibrating the cadence to the organization's own risk environment, mission, and operational tempo rather than prescribing a universal interval. The rationale is that circumstances such as organizational missions, business functions, environments of operation, technologies, or threat change over time, making periodic repetition of certain activities necessary and the appropriate interval something each organization must judge for itself. In practice, it appears throughout NIST control catalogs as an *Assignment* notation — e.g., `[Assignment: organization-defined frequency]` — wherever a control mandates a recurring action and leaves the interval open for the organization to specify, with implementers then documenti