Field notebook · source record
AC-4(13)
Access ControlDecomposition into Policy-relevant Subcomponents
The statement below is source material, not a generated control summary.
Source statement
When transferring information between different security domains, decompose information into {{ insert: param, ac-04.13_odp }} for submission to policy enforcement mechanisms.
Guidance
Decomposing information into policy-relevant subcomponents prior to information transfer facilitates policy decisions on source, destination, certificates, classification, attachments, and other security- or privacy-related component differentiators. Policy enforcement mechanisms apply filtering, inspection, and/or sanitization rules to the policy-relevant subcomponents of information to facilitate flow enforcement prior to transferring such information to different security domains.
Organization-defined parameters
Organization-defined · unresolvedCatalog reference only. No project value has been assigned or evaluated here.
- ac-04.13_odp
policy-relevant subcomponents
Source guidance- policy-relevant subcomponents into which to decompose information for submission to policy enforcement mechanisms are defined;
Assessment reference context
Retained, not activated.1 source assessment records and 1 objective nodes are available as reference context. This surface runs none of them.
ac-4.13_objAC-04(13)1 objective nodes
- when transferring information between different security domains, information is decomposed into {{ insert: param, ac-04.13_odp }} for submission to policy enforcement mechanisms.
Reference method and authority
- InputExact release, source digest, control ID, and cited source fields
- Agent taskPrepare a bounded evidence request or test-plan draft
- Fail closedAbstain when source, scope, or assessment identity is missing
- Human acceptanceA named reviewer decides whether evidence supports the conclusion