Field notebook · source record
AC-4(1)
Access ControlObject Security and Privacy Attributes
The statement below is source material, not a generated control summary.
Source statement
Use {{ insert: param, ac-4.1_prm_1 }} associated with {{ insert: param, ac-4.1_prm_2 }} to enforce {{ insert: param, ac-04.01_odp.09 }} as a basis for flow control decisions.
Guidance
Information flow enforcement mechanisms compare security and privacy attributes associated with information (i.e., data content and structure) and source and destination objects and respond appropriately when the enforcement mechanisms encounter information flows not explicitly allowed by information flow policies. For example, an information object labeled Secret would be allowed to flow to a destination object labeled Secret, but an information object labeled Top Secret would not be allowed to flow to a destination object labeled Secret. A dataset of personally identifiable information may be tagged with restrictions against combining with other types of datasets and, thus, would not be allowed to flow to the restricted dataset. Security and privacy attributes can also include source and destination addresses employed in traffic filter firewalls. Flow enforcement using explicit security or privacy attributes can be used, for example, to control the release of certain types of information.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-4.1_prm_1
organization-defined security and privacy attributes
- ac-4.1_prm_2
organization-defined information, source, and destination objects
- ac-04.01_odp.01
security attributes
Source guidance- security attributes to be associated with information, source, and destination objects are defined;
- ac-04.01_odp.02
privacy attributes
Source guidance- privacy attributes to be associated with information, source, and destination objects are defined;
- ac-04.01_odp.03
information objects
Source guidance- information objects to be associated with information security attributes are defined;
- ac-04.01_odp.04
information objects
Source guidance- information objects to be associated with privacy attributes are defined;
- ac-04.01_odp.05
source objects
Source guidance- source objects to be associated with information security attributes are defined;
- ac-04.01_odp.06
source objects
Source guidance- source objects to be associated with privacy attributes are defined;
- ac-04.01_odp.07
destination objects
Source guidance- destination objects to be associated with information security attributes are defined;
- ac-04.01_odp.08
destination objects
Source guidance- destination objects to be associated with privacy attributes are defined;
- ac-04.01_odp.09
information flow control policies
Source guidance- information flow control policies as a basis for enforcement of flow control decisions are defined;
Assessment reference context
Retained, not activated.1 source assessment records and 2 objective nodes are available as reference context. This surface runs none of them.
ac-4.1_objAC-04(01)2 objective nodes
- {{ insert: param, ac-04.01_odp.01 }} associated with {{ insert: param, ac-04.01_odp.03 }}, {{ insert: param, ac-04.01_odp.05 }} , and {{ insert: param, ac-04.01_odp.07 }} are used to enforce {{ insert: param, ac-04.01_odp.09 }} as a basis for flow control decisions;
- {{ insert: param, ac-04.01_odp.02 }} associated with {{ insert: param, ac-04.01_odp.04 }}, {{ insert: param, ac-04.01_odp.06 }} , and {{ insert: param, ac-04.01_odp.08 }} are used to enforce {{ insert: param, ac-04.01_odp.09 }} as a basis for flow control decisions.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion