organization-defined security function
** A placeholder construct used in control frameworks — most prominently NIST SP 800-53 and NIST SP 800-171 — where a security control statement is intentionally left partially open, requiring each implementing organization to enumerate the specific security-enforcing capabilities (hardware, software, or firmware mechanisms such as account management, access authorization configuration, audit-event settings, and intrusion-detection parameter management) that are subject to the control's requirement. It functions as an *assignment operation*: a control parameter that allows an organization to assign a specific, organization-defined value to the control or control enhancement. In practice, many NIST controls are not "complete" as published but require "fill in the blanks," and these blanks are called Organization-defined Values or Organization-defined Parameters; "organization-defined security functions" is one such parameter, naming whichever protective capabilities the organization determines fall under least-privilege or access-authorization scope — for example, establishing system accounts and assigning privileges, installing software, configuring access authorizations, configuri