Field notebook · source record
AC-3(9)
Access ControlControlled Release
The statement below is source material, not a generated control summary.
Source statement
Release information outside of the system only if: The receiving {{ insert: param, ac-03.09_odp.01 }} provides {{ insert: param, ac-03.09_odp.02 }} ; and {{ insert: param, ac-03.09_odp.03 }} are used to validate the appropriateness of the information designated for release.
Guidance
Organizations can only directly protect information when it resides within the system. Additional controls may be needed to ensure that organizational information is adequately protected once it is transmitted outside of the system. In situations where the system is unable to determine the adequacy of the protections provided by external entities, as a mitigation measure, organizations procedurally determine whether the external systems are providing adequate controls. The means used to determine the adequacy of controls provided by external systems include conducting periodic assessments (inspections/tests), establishing agreements between the organization and its counterpart organizations, or some other process. The means used by external entities to protect the information received need not be the same as those used by the organization, but the means employed are sufficient to provide consistent adjudication of the security and privacy policy to protect the information and individuals’ privacy. Controlled release of information requires systems to implement technical or procedural means to validate the information prior to releasing it to external systems. For example, if the system passes information to a system controlled by another organization, technical means are employed to validate that the security and privacy attributes associated with the exported information are appropriate for the receiving system. Alternatively, if the system passes information to a printer in organization-controlled space, procedural means can be employed to ensure that only authorized individuals gain access to the printer.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-03.09_odp.01
system or system component
Source guidance- the outside system or system component to which to release information is defined;
- ac-03.09_odp.02
controls
Source guidance- controls to be provided by the outside system or system component (defined in AC-03(09)_ODP[01]) are defined;
- ac-03.09_odp.03
controls
Source guidance- controls used to validate appropriateness of information to be released are defined;
Assessment reference context
Retained, not activated.1 source assessment records and 2 objective nodes are available as reference context. This surface runs none of them.
ac-3.9_objAC-03(09)2 objective nodes
- information is released outside of the system only if the receiving {{ insert: param, ac-03.09_odp.01 }} provides {{ insert: param, ac-03.09_odp.02 }};
- information is released outside of the system only if {{ insert: param, ac-03.09_odp.03 }} are used to validate the appropriateness of the information designated for release.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion