organizational system
An information system — comprising hardware, software, firmware, data, personnel, and associated facilities — that is owned, operated, or controlled by or on behalf of an organization and falls within that organization's authorization boundary and governance responsibility. It is the entity inside whose authorization boundary services and components reside, as distinct from external system services used by but not part of the system. In NIST's Risk Management Framework and related publications (SP 800-53 Rev. 5, SP 800-171 Rev. 3, SP 800-37 Rev. 2), the term serves as the consistent scope marker for applying security and privacy controls: organizations employ configuration settings, access controls, and other safeguards on the commercial IT products that compose their organizational systems. The controls in SP 800-53 are designed to protect organizational operations and assets through an organization-wide risk management process applied to these systems.