Field notebook · source record
AC-4(10)
Access ControlEnable and Disable Security or Privacy Policy Filters
The statement below is source material, not a generated control summary.
Source statement
Provide the capability for privileged administrators to enable and disable {{ insert: param, ac-4.10_prm_1 }} under the following conditions: {{ insert: param, ac-4.10_prm_2 }}.
Guidance
For example, as allowed by the system authorization, administrators can enable security or privacy policy filters to accommodate approved data types. Administrators also have the capability to select the filters that are executed on a specific data flow based on the type of data that is being transferred, the source and destination security domains, and other security or privacy relevant features, as needed.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-4.10_prm_1
organization-defined security or privacy policy filters
- ac-4.10_prm_2
organization-defined conditions
- ac-04.10_odp.01
security filters
Source guidance- security policy filters that privileged administrators have the capability to enable and disable are defined;
- ac-04.10_odp.02
privacy filters
Source guidance- privacy policy filters that privileged administrators have the capability to enable and disable are defined;
- ac-04.10_odp.03
conditions
Source guidance- conditions under which privileged administrators have the capability to enable and disable security policy filters are defined;
- ac-04.10_odp.04
conditions
Source guidance- conditions under which privileged administrators have the capability to enable and disable privacy policy filters are defined;
Assessment reference context
Retained, not activated.1 source assessment records and 2 objective nodes are available as reference context. This surface runs none of them.
ac-4.10_objAC-04(10)2 objective nodes
- capability is provided for privileged administrators to enable and disable {{ insert: param, ac-04.10_odp.01 }} under {{ insert: param, ac-04.10_odp.03 }};
- capability is provided for privileged administrators to enable and disable {{ insert: param, ac-04.10_odp.02 }} under {{ insert: param, ac-04.10_odp.04 }}.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion