NIST SP 800-53 – AC-4 – Information Flow Enforcement Control(s) Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on [Assignment:...
NIST SP 800-53 – AC-4(1) – Information Flow Enforcement | Object Security and Privacy Attributes Control(s) Use [Assignment: organization-defined security and privacy attributes] associated with [Assignment: organization-defined information, source, and destination objects] to enforce [Assignment:...
NIST SP 800-53 – AC-4(2) – Information Flow Enforcement | Processing Domains Control(s) Use protected processing domains to enforce [Assignment: organization-defined information flow control policies] as a basis for flow control decisions....
NIST SP 800-53 – AC-4(3) – Information Flow Enforcement | Dynamic Information Flow Control Control(s) Enforce [Assignment: organization-defined information flow control policies]. Additional Details (Discussion) Organizational policies regarding dynamic information flow control include allowing...
NIST SP 800-53 – AC-4(4) – Information Flow Enforcement | Flow Control of Encrypted Information Control(s) Prevent encrypted information from bypassing [Assignment: organization-defined information flow control mechanisms] by [Selection (one or more): decrypting the information;...
NIST SP 800-53 – AC-3(5) – Access Enforcement | Security-relevant Information Control(s) Prevent access to [Assignment: organization-defined security-relevant information] except during secure, non-operable system states. Additional Details (Discussion) Security-relevant information is...
NIST SP 800-53 – AC-4(5) – Information Flow Enforcement | Embedded Data Types Control(s) Enforce [Assignment: organization-defined limitations] on embedding data types within other data types. Additional Details (Discussion) Embedding data types within...
NIST SP 800-53 – AC-15 – Automated Marking Control(s) [Withdrawn: Incorporated into MP-3.] Additional Details (Discussion) N/A Related Control(s) Reference(s) NIST SP 800-53 Rev-5
NIST SP 800-53 – AC-4(6) – Information Flow Enforcement | Metadata Control(s) Enforce information flow control based on [Assignment: organization-defined metadata]. Additional Details (Discussion) Metadata is information that describes the characteristics...
NIST SP 800-53 – AC-3(7) – Access Enforcement | Role-based Access Control Control(s) Enforce a role-based access control policy over defined subjects and objects and control access based upon [Assignment: organization-defined roles...