Field notebook · source record
AC-3(15)
Access ControlDiscretionary and Mandatory Access Control
The statement below is source material, not a generated control summary.
Source statement
Enforce {{ insert: param, ac-3.15_prm_1 }} over the set of covered subjects and objects specified in the policy; and Enforce {{ insert: param, ac-3.15_prm_2 }} over the set of covered subjects and objects specified in the policy.
Guidance
Simultaneously implementing a mandatory access control policy and a discretionary access control policy can provide additional protection against the unauthorized execution of code by users or processes acting on behalf of users. This helps prevent a single compromised user or process from compromising the entire system.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-3.15_prm_1
organization-defined mandatory access control policy
- ac-3.15_prm_2
organization-defined discretionary access control policy
- ac-03.15_odp.01
mandatory access control policy
Source guidance- a mandatory access control policy enforced over the set of covered subjects specified in the policy is defined;
- ac-03.15_odp.02
mandatory access control policy
Source guidance- a mandatory access control policy enforced over the set of covered objects specified in the policy is defined;
- ac-03.15_odp.03
discretionary access control policy
Source guidance- a discretionary access control policy enforced over the set of covered subjects specified in the policy is defined;
- ac-03.15_odp.04
discretionary access control policy
Source guidance- a discretionary access control policy enforced over the set of covered objects specified in the policy is defined;
Assessment reference context
Retained, not activated.1 source assessment records and 4 objective nodes are available as reference context. This surface runs none of them.
ac-3.15_objAC-03(15)4 objective nodes
- {{ insert: param, ac-03.15_odp.01 }} is enforced over the set of covered subjects specified in the policy;
- {{ insert: param, ac-03.15_odp.02 }} is enforced over the set of covered objects specified in the policy;
- {{ insert: param, ac-03.15_odp.03 }} is enforced over the set of covered subjects specified in the policy;
- {{ insert: param, ac-03.15_odp.04 }} is enforced over the set of covered objects specified in the policy.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion