Organization-Defined Parameter
An Organization-Defined Parameter is the fill-in-the-blank part of a security control that an organization sets to fit its own environment. For example, a control may require accounts to lock after a certain number of failed login attempts, and the ODP is the specific number the organization chooses. This flexibility lets a control be customized rather than applied as a fixed, one-size-fits-all rule.
An ODP is the variable part of a control, control enhancement, or security requirement that is instantiated by an organization during the tailoring process, generally by assigning an organization-selected value to that variable. ODPs enable customization of control implementation, such as specifying thresholds like the number of unsuccessful logon attempts before an account is locked. Per the evidence, the concept originates in NIST terminology (as reflected in the NIST CSRC glossary), and the U.S. Department of Defense has published ODPs associated with NIST SP 800-171. Readers should verify the specific control set, revision, and any applicable DoD or agency-published ODP values against current authoritative sources, as parameters and the requirements referencing them may vary by revision and tailoring context.
Why it matters
Organization-Defined Parameters sit at the intersection of standardization and flexibility, which is precisely why they matter so much in defense and public sector compliance. A control set can define a common structure and intent, but leaving certain values as ODPs allows each organization to right-size the control to its own risk environment, mission needs, and operational realities. The catch is that this flexibility does not eliminate accountability: when an organization selects a value for an ODP, that choice becomes the standard against which its implementation will be assessed. A poorly justified or overly permissive parameter can undermine the protective intent of the control even when the organization technically remains within the control's language.
The stakes rose for the defense industrial base when the U.S. Department of Defense published ODPs associated with NIST SP 800-171. Where a requirement previously might have left a value open to contractor discretion, a DoD-published ODP can effectively remove that discretion by specifying the value the government expects. This shifts ODPs from an internal tailoring exercise to a contractual and assessment consideration for organizations handling Controlled Unclassified Information. Compliance officers and assessors should not assume that a self-selected parameter will satisfy a government reviewer if an authoritative ODP value has been published for that requirement.
A common expert-level caution applies here: parameters and the requirements that reference them may change across revisions and tailoring contexts, and a value that was acceptable under one revision or agency baseline is not automatically valid elsewhere. Because ODP values can vary by control set, revision, and whether DoD or an agency has published its own values, readers should treat any specific parameter as something to verify against current authoritative sources rather than as a fixed, universal number.
Who it's relevant to
Inside ODP
Common questions
Answers to the questions practitioners most commonly ask about ODP.